MIOES Cybersecurity PWS DRFP Inc3.pdf

PDF 394 KB Posted

Attached to
MDA IT Operations & Engineering Solutions (MIOES) - CANCELED Federal contract opportunity
Solicitation number
HQ0857-MIOES-ZA
Issued by
DOD Missile Defense Agency

About this file

This document is a Cybersecurity Services Performance Work Statement (PWS) that supports the Missile Defense Agency's (MDA) IT services and resources. The primary scope of this PWS encompasses cybersecurity and Defensive Cyber Operations (DCO) actions required to operate and protect DoD IT systems.

Key details include:

  • The PWS covers tasks such as cybersecurity configuration, Risk Management Framework (RMF) implementation, cybersecurity project integration, and 24/7 DCO detect actions.
  • The contractor shall provide task order-level leadership, management, administration, and integration activities to execute the PWS requirements.
  • Deliverables include a Cybersecurity Resiliency Management Plan, Integrated Program Management Data and Analysis Report, Data Accession List, and Task Order Close-Out Report.
  • The PWS specifies performance standards and requirements for each task area, including compliance with DoD and MDA cybersecurity policies, regulations, and directives.

View the file

Other files for this federal contract opportunity

Other files attached to MDA IT Operations & Engineering Solutions (MIOES) - CANCELED, newest first.
File Type Posted
MIOES_IRES PWS -- Enterprise IT (12.20 RFI).pdf PDF
MIOES CLIN Structure RFI 12.20.2024.pdf PDF
MIOES Virtual Industry Brief Schedule.pdf PDF
MIOES Industry Day Overview and Instructions 9.27.2024.docx DOCX document
MDIOC Tour Request Form 9.27.2024.xlsx XLSX spreadsheet
MIOES DRFP Exhibit C CDRL Instructions.pdf PDF
MIOES MDIOC Tour Request.pdf PDF
MIOES DRAFT CLIN Structure DRFP Inc3.pdf PDF
MIOES Section L DRFP Inc2 Rev1.docx DOCX document
MIOES Section L DRFP Inc2.docx DOCX document
Attachment L-5 MIOES Question Matrix DRFP Inc2.xlsx XLSX spreadsheet
Attachment L-6 MIOES Evaluation Scenarios DRFP Inc2.docx DOCX document
MIOES Basic IDIQ PWS 24 June DRAFT RFP.pdf PDF
QA_DRFP_Inc1_MIOES.xlsx XLSX spreadsheet
MIOES Phase-In Task Order PWS 14 June DRAFT RFP.pdf PDF
MIOES Basic IDIQ PWS 14 June DRAFT RFP.pdf PDF
22F8004_PWS.pdf PDF
22F8003_PWS.pdf PDF
23F4100_PWS.pdf PDF
MIOES Industry Monthly April 2024.pdf PDF
22F5900_PWS.pdf PDF
18F8002_PWS.pdf PDF
23F8700_PWS.pdf PDF
23F1500_PWS.pdf PDF
MIOES OCI Guiding Principles (Final).pdf PDF
IRES_AttchJ-01_Encl1_HLO.docx DOCX document
20230103-MIOES_Industry_Day_POC-1.xlsx XLSX spreadsheet
20221110-MIOES_Industry_Day_POC.xlsx XLSX spreadsheet
MIOES_Industry_Day_POC.xlsx XLSX spreadsheet
Sections A-K (A0007).pdf PDF
Attachment J-06 - PEIP.pdf PDF
Attachment J-07 - Compliance Documents List.docx DOCX document
Attach L-01 - Library Request Form v2.2.pdf PDF
Attach L-03 - OCI Disclosure Form v2.0 (Extended).pdf PDF
Attach L-04 - CDM.xlsx XLSX spreadsheet
Attach L-08 - Transition SOO (A0002).docx DOCX document
Attach L-09 - IRES TO Award-Modification Process.docx DOCX document
Attach L-13 - IRES ERI Data.xlsx XLSX spreadsheet
Attach L-15 - Cost Price WB 2 (A0001).xlsx XLSX spreadsheet
Attachment J-01 - IRES Contract SOO (A0005).docx DOCX document
Attachment J-04 - DD254.pdf PDF
Attach L-10 - IRES SEPI SOO (A0006).docx DOCX document
Attach L-17 - Tool App Questionnaire (A0005).docx DOCX document
Section L (A0008).docx DOCX document
Attachment J-03 - IRES Labor Category Descriptions.xlsx XLSX spreadsheet
Exhibit A - MDA Mandatory CDRLs.docx DOCX document
Exhibit B - IRES CDRLs.docx DOCX document
Attach L-06 - Client Authorization Letter.docx DOCX document
Attach L-11 - EITS SOO (A0005).docx DOCX document
Attach L-12 - FEO SOO (A0005).docx DOCX document
Show all 50

MDA IT Operations & Engineering Solutions (MIOES) - CANCELED has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CYBERSECURITY SERVICES PERFORMANCE WORK STATEMENT 1

1.0 Background 3

Cybersecurity personnel secure, defend, and preserve data, networks, net-centric capabilities, and 5 other designated systems by ensuring appropriate security controls and measures are in place, and 6 taking defensive actions. This includes access to system controls, monitoring, administration, and 7 integration of cybersecurity into all aspects of engineering and acquisition of cyberspace 8 capabilities. 9 The integrity, confidentiality, and availability of IT systems and data is critical to accomplishing 11 the Missile Defense Agency’s (MDA) mission. This effort not only work towards hardening 12 information systems, reducing the attack surface of cyber terrain, and enhancing a more proactive 13 defense core, but also develop innovative approaches to enhance defenses without sacrificing the 14 user experience. 15 The interpretation and implementation of Missile Defense Agency (MDA), National Institute of 17 Standards and Technology (NIST), Chairman of the Joint Chiefs of Staff Instruction (CJCSI) and 18 Department of Defense DoD issuances, including applicable laws, statutes, Presidential Directives, 19 executive branch guidelines, and/or administrative/criminal legal guidelines and procedures 20 relevant to cybersecurity will be critical to this task order. This includes all aspects of integrating 21 information security and risk management activities into the system development life cycle and 22 supporting ongoing authorizations. Activities associated with a system, encompassing the 23 system’s initiation, development and acquisition, implementation, operation and maintenance, and 24 ultimately its disposal that instigates another system initiation. Validate current, future, and 25 emerging technologies that will help the MDA continuously monitor and assess terrain to assess 26 and mitigate risk. 27

2.0 Scope 29

This PWS supports the MDA CIO's mission to ensure that the MDA's IT services and resources 30 are administered, acquired, managed, operated, and cyber defended in compliance with the goals 31 and directives of existing statutes and DoD regulations and the priorities set by the MDA 32 Director and MDA CIO. The primary scope of this PWS encompasses both the cybersecurity and 33 Defensive Cyber Operations (DCO) actions required to operate and protect DoD IT systems. 34 This is a Firm-Fixed Price task order. 36

3.0 Reserved 38

4.0 Reserved 40

5.0 CRDL 42

The point of delivery for all CDRL products, except as noted in Exhibit C, is the MDA 43 Electronic Content and Records Tool (E-CaRT) system. The contractor shall deliver all such 44 products by saving and profiling them in E-CaRT, with the appropriate notification of delivery 45 letter transmitted electronically to the Government’s Data Management Office (DMO). 46 Reference Exhibit C for specific CDRL delivery instructions. 47

Task CDRL DID Title

10.1.2 TBD DI-MGMT-80368A Status Report

10.2.1 TBD Cybersecurity Resiliency Management Plan

10.2.2 TBD Integrated Program Management Data and Analysis Report

(IPMDAR) (Modified)

10.2.3 TBD Data Accession List

10.2.4 TBD Task Order Close-Out Report

6.0 Milestones 50

• TBD 51

7.0 Government Property 53

• TBD 54

8.0 Facts 56

• TBD 57

9.0 Applicable Directives/Regulations 59

• TBD 61

10.0 Performance Requirements (Firm Fixed Price) 63

10.1 MIOES Contract Level Management 65

Reference Basic PWS 66

10.2 Task Order Management 68

10.2.1 Task Order Program Management and Leadership 70

The contractor shall provide task order (TO)-level leadership, management, administration, and 71 integration activities required to execute TO requirements within the integrated framework of the 72 contract. 73 Standards: 75

• Manage technical, cost, and schedule performance and associated risks and report at the 76 Risk Review Boards. 77

• Provide situational awareness, report status and insight on technical, cost, schedule 78 performance, significant accomplishments; customer concerns or issues; TO risks and 79 mitigation status; performance against the PWS objective measurements outlined in the 80 Quality Assurance Surveillance Plan (QASP), and identify, track, and share performance 81 trends. (CDRL) 82

• Lead, manage, and execute TO activities in accordance with the MIOES Program 83 Management Plan. 84

• Deliver proposals IAW with the timelines identified in the RFP letter from the PCO, for 85 TO modifications and any follow-on TO, and prepare proposal related artifacts required 86 to participate in Integrated Product Teams associated with proposal development for TO 87 modifications and the follow-on TO. 88

• Prepare for and participate in mandated audits, such as Inspector General, IT security, 89 physical security, environmental, health and safety, GAO, and property. 90

• Manage export control requirements to comply with DoD and MDA requirements, 91 including International Traffic in Arms Regulations (ITAR) (22 Code of Federal 92 Regulations [CFR] 120-130) and technical assistance agreements processes, as required. 93

• Comply with the MDA and MDIOC Facility Systems Engineering Plans (SEP) 94

• Provide cleared, cyber workforce certified IAW DoD 8140.03 with the required skills, 95 knowledge and ability to execute the requirements of the PWS. 96

• Enter all roles being filled by the contractor in the MDA Cyber Workforce Qualifications 97

Tracker (CWQT) IAW MDA 8140.01-INS 98 o Include the following information for each role: 99

Position Title 100 Position Description 101 DCWF Cyber Code Alignment 102 Required Security Clearance 103 Position Sensitivity 104 System Privilege Level 105 DOD 8570.01-M and DODD 8140.01 106

• Review the document annually to ensure that all contractor filled positions within the 107 CSSP are accurately captured 108

• Develop and deliver an MDA Cybersecurity Resiliency Management Plan for all MDA 109 authorized systems based on the Joint Staff J6 Cyber Survivability Endorsement (CSE) 110 Implementation Guide. (CDRL XXXX). 111

• Lead, manage, and execute TO activities in accordance with the Cyber Resilience 112 Management Plan 113

• The contractor shall develop a training plan for contractor personnel supporting the CSSP 114 that aligns with the DoD Cyber Workforce Framework (DCWF) 115 (https://cyber.mil/wid/dcwf/). The contractor will not be held to the certification 116 standards until DFARS 252.239-7001 is updated. 117

10.2.2 Task Order Measurement and Control 119

https://cyber.mil/wid/dcwf/

The contractor shall monitor, measure, control, and report schedule and performance metrics at 120 the TO level. 121 Standards: 123

• Deliver a modified Integrated Program Management Data and Analysis Report 124 (IPMDAR)—Schedule only (CDRL) 125

• Perform a Schedule Baseline Review within 90 days of contract award. 126

• Integrate the TO Integrated Master Schedule (IMS) into the MIOES Integrated Schedule 127

(IIS) 128

• Provide subcontracting and limitation of funds oversight, and execution of TO 129 modifications and awards 130

• Provide management, oversight and quality control for program control documentation, 131 processes, and reports. 132

10.2.3 Data Accession List (TO Level) 134

The contractor shall provide a Data Accession List (DAL). 135

• Deliver the DAL, providing a medium for identifying contractor internal data which has 137 been generated. (CDRL) 138

• Provide a document reference number for each DAL item for rapid retrieval from 139 contractor data sources. 140

10.2.4 Task Order Close-Out 143

The contractor shall close out the task order to enable a continuity of effort for all contracted 144 activities. 145 Standards: 147

• Perform a TO closeout that consolidates all TO data at the end of the TO and deliver a 148 draft Task Order Close-Out Report 6 months prior to the end of the period of 149 performance and a final report within 3 months from the end of the period of 150 performance. (CDRL) 151

• Include a roll-up of historical TO data and a summary of TO activities, including 152 participating companies (to include size status, large business or small business, and 153 socio-economic category if a small business), a TO summary, and the status of ongoing 154 work at the point of transition. 155

• Include the following TO data; 156 o A Contractor-Acquired Property report to include all mandatory data fields for each 157 item as well as identification of the Material Inspection and Receiving Report 158 number associated with delivery of each item in Wide Area Workflow; 159 o A statement confirming that all DAL items are considered ordered and delivered 160 IAW DFARS clause 252.227-7027, Deferred Ordering of Technical Data or 161 Computer Software; 162 o A list of CDRLs and DALs delivered under the TO; 163 o DD Form 882, Report of Inventions and Subcontracts; 164 o Statement of Performance Completion; and 165 o Small Business Subcontractor Utilization Report 166

10.2.5 Cyber Tracking and Reporting: 168

Many of the tasks and associated standards of this PWS require the continuous integrated 170 tracking and reporting of key indicators of risk (KIORS) for information system security 171 throughout the systems lifecycle. Examples include the following: 172

• Assessment of current environment(s) and identifying non-compliancy. 173

• Reporting of cyber defense trend analysis. 174

• Reviews and updates of the status of key indicators of risk (KIOR). 175 o Password Configuration and compliance 176 o Hardware with EOL date within 6 months 177 o Software with EOS date within 6 months 178 o EOL/EOS assets still in use 179 o Unresolved highly exploitable vulnerabilities (internal/external) 180

• Tracking all assets; 181 o Must include vendor, version number(s) 182 o End-of-life or end-of-support dates 183 o Customer usage (quantity and 2/3 LTR) 184 o Dependencies 185 o System of Record (eMass authorization) 186 o Any Support Agreement with POP 187 o Ability to highlight/filter. 188

• Continuous monitoring of vulnerabilities that cannot be patched or mitigated within the 189 Agency defined timelines. 190

• Capture and review of STIG results and reporting to Government. 191

• Initiation of corrective actions and track deviations. 192

The contractor shall develop and deliver within 6 months of award a real-time, continuous, 194 automated reporting capability with cross-functional data. 195 Standards: 197

• Ingest data continuously from authoritative data sources into dashboards 198

• Provide a trend of overall risk to each program (2-letter organization) with the ability to 199 filter by each system of record. 200

• Control the dashboards by role-based access by name and by group. 201

10.3 Cybersecurity: 203

10.3.1 Local Control Center (LCC): 204

10.3.1.1 The contractor shall perform self-assessments of systems and networks and identify 206 systems/networks that deviate from acceptable configurations, enclave policy, or local policy 207 then recommend internal defense actions. 208

Standards: 210

• Perform cybersecurity activities, roles, and responsibilities that fall under the "subscriber" 211 section of the MDA CSSP SLA, on-site and during core business hours. 212

• Develop, review, and update repeatable processes, procedures, and templates to 213 standardize and streamline risk and vulnerability self-assessments annually. 214

• Implement and assure functionality of security requirements and appropriate information 215 technology (IT) policies and procedures that are consistent with the Agency mission and 216 goals. 217

• Interpret patterns of noncompliance to determine their impact on levels of risk, exploits 218 and/or overall effectiveness of the enterprise’s cybersecurity program; 219 o Identify and prioritize mitigation and remediation of Common Vulnerability and 220 Exposure (CVEs) that have a high probability of being exploited. 221 o Generate and execute government approved plan of action and milestones in 222 government provided tools to bring non-compliant assets into compliance within 223 specified timeframes. 224 o Identify possible security violations and report any suspected security incidents 225 (including unauthorized access) involving hardware, software, firmware, 226 networks, infrastructure, or sensitive data occurring on any physical, virtual, or 227 cloud-based systems IAW NIST SP 800-61 Rev 2, Computer Security. 228 o Incident Handling Guide and CJCSM 6510.01B, Cyber Incident Handling 229 Program. 230

• Comply with MDA security incident management policies, responsibilities, and 231 procedures for timely reporting of incidents and other significant events of interest to 232 Missile Defense Agency (MDA) leadership IAW MDA INSTRUCTION 3000.08-INS, 233 Incident Reporting. 234

• Establish a standard collection of processes and tools, track/revision changes, and 235 provide up-to-date documentation, in a centralized configuration management program. 236

• Ensure plans of actions and milestones or remediation plans are in place for 237 vulnerabilities identified during risk assessments, audits, inspections, etc.; 238 o Provide continuous updates of POA&Ms for all systems/enclaves for all 239 vulnerabilities; Ensure no late POA&Ms or overdue CTOs applicable to any 240 contractor-managed IT environments. 241

10.3.1.2 The contractor shall assess systems and networks to validate the environment(s) are in a 243 “ready state” for cybersecurity inspections at all times. 244 Standards: 246

• Analyze organization’s cybersecurity policies and configurations; evaluate compliance 247 with regulations and organizational directives annually. Update as needed and submit to 248 Government ISSM for approval/coordination. 249

• Consolidate, optimize, and standardize to reduce the attack surface and exploitable 250 technology footprint 251

• Deploy and configure Endpoint Security IAW JFHQ-DODIN OPORD 8600 252

• Resolve Tier II/III reported data and appropriate follow-up actions; 253 o Terrain (network address declaration) is covered by CSSP 254

• Manage Network Vulnerability Scan Coverage IAW JFHQ-DODIN TASKORD 20-0020 255

• Appoint personnel to monitor and review auditing/logging; 256 o Auditing/logging is configured and enabled in accordance with STIG/SRGs. 257

• Monitor and evaluate the effectiveness of the enterprise’s cybersecurity safeguards to 258 ensure they provide the intended level of protection; 259 o Perform self-assessments of systems and networks IAW DoD and Agency 260 guidelines; identify deviation from acceptable configurations, enclave policy, or 261 local policy. Some examples include: the vulnerability scanning results, 262 SRG/STIG checklists, quarantining, application blacklisting and whitelisting), and 263 reporting using the Agency’s defined tool set necessary for these functions. 264 o Prepare reports that identify technical and procedural findings; Provide 265 recommended remediation strategies/solutions to Government ISSM and PM. 266

10.3.1.3 The contractor shall perform Tier III Internal Network and Security Monitoring entity 268 for systems owned and operated by the MDA CIO. 269 Standards: 271

• Monitor the internal local network 24/7/365. Monitoring can be performed utilizing 272 automated technologies to offset the cost of personnel 273

• Identify and investigate anomalous activity, whether related to system health or 274 maintenance. Report anomalous events detected to the ISSM, AO, CSSP, and 275 information owners 276

• Provide copies of audit and system logs as requested by the CSSP point of contact for 277 correlation activities and requirements from USCYBERCOM and/or JFHQ-DODIN 278

• Correlate vulnerability management data with network and endpoint security monitoring 279 to provide fewer false positives and a higher level of fidelity for incident detection, 280 handling, and countermeasures 281

• Report, track and execute corrective actions for all cyber events and incidents identified 282 internally or by the CSSP within the timelines identified in CJCSI 6510.01B 283

• Verify, validate, and articulate the operational impact on incidents and report to the CSSP 284

• Coordinate with the CSSP to acquire and preserve copies of digital media, logs, and 285 investigative and technical data associated with cyber intrusion incidents, investigations, 286 and operations required for tactical analysis, strategic analysis, or law enforcement 287 investigations 288

• Safeguard and deliver all information related to incidents upon request from the CSSP. 289

• Retain all incident artifacts and documentation in accordance with the approved records 290 disposition schedule IAW DoDI 8530.03. 291 o Collected data will be shared with the CSSP via means specified by the CSSP, 292 upon request. 293

• Coordinate with the CSSP to conduct incident close out activities as authorized or 294 directed once coordinated response actions have been completed 295

• Coordinate with the CSSP to conduct post incident after action review, at a minimum to 296 identify lessons learned. 297

• Analyze incidents to produce coherent and actionable information in support of time-298 critical operational decisions 299

• 300

10.3.2 Cybersecurity Configuration: 301

10.3.2.1 The contractor shall continuously monitor managed networks and enclaves to identify 303 unauthorized hardware/software products and/or versions; 304 Standards: 306

• Ensure no instance of EOL or End-of-Service (EOL/EOS) hardware or software exists in 307 any contractor-managed IT environment, unless accepted by the AO in a risk mitigation 308 plan or POA&M. 309

• Develop, review and update repeatable processes, procedures, and templates to 310 standardize and streamline assessing change in the risk posture annually. 311

• Monitor and evaluate a system’s compliance with information technology (IT) security, 312 resilience, and dependability requirements every 6 months; 313 o Review all hardware and software in use and update system of record. 314 o Review and update network topologies as necessary 315 o Assess to ensure only supported versions of software, firmware, and hardware 316 products in the boundary network and internal network. 317 o Coordinate the removal/update of no longer supported versions of software, 318 firmware, and hardware products and/or obtain extended support agreement with 319 the vendor. 320

• Annual review of vendor/company ownership of assets in use within the Agency. 321 o Identify changes with non-US equities. 322 o Submit for supply chain review (as required) 323 o Reassess risk and update the system of record 324

10.3.2.2 The contractor shall manage Ports, Protocols and Services Management (PPSM) 326 program IAW DODI 8551.01, Ports, Protocols, and Services Management and RMF security 327 controls. 328 Standards: 330

• Establish a standard in support of cross-boundary integration between MDA assets 331 (internal and external). 332

• Identify and document Port, Protocols, and Data Services under the authority of an 333 information system (as defined by DoDI 8500.01, Cybersecurity) to satisfy artifact 334 requirements for RMF security controls. 335

• Develop PPSM artifacts that document the PPSM lifecycle as it relates to MDA systems. 336

• Maintain registry database to track the Ports, Protocols, and Services used by each 337 information system/application/operating system. 338

• Conduct evaluations and assessments of the inherent vulnerabilities associated with the 339 use of specific Ports, Protocols, and Services across network boundaries and remediate 340

• Ensures that use of Ports, Protocols, and Services are controlled and regulated to guard 341 against damage to operations. 342

10.3.2.3 The contractor shall perform security assessments on Information Assurance enabled 344 hardware products not previously reviewed. 345 Standards: 347

• Assess supply chain risk management and validate vendor dependencies meet 348 organizational design standards, policies, and authorized approaches to maintain 349 compliance throughout the lifecycle. 350

• Ensure IA enabled hardware products are vendor supported. 351

• Identify and address security implications including risk acceptance and documentation, 352 common criteria, and methods of independent testing. 353

• Prepare reports that identify technical and procedural findings; Provide recommended 354 remediation strategies/solutions to Government ISSM and PM. 355

• Develop repeatable processes, procedures, and templates to standardize and streamline 356 the review of new IA enabled products and services. 357

10.3.2.4 The contractor shall perform code analysis and provide a risk assessment for new 359 customer-submitted software requests. (~ 450 new submissions annually) 360 Standards: 361

• Assess supply chain risk management and validate vendor dependencies meet 362 organizational design standards, policies, and authorized approaches to maintain 363 compliance throughout the lifecycle. 364

• Perform software security assessments on products not previously reviewed; 365 o Identify basic common coding flaws at a high level. 366 o Identify security issues around steady state operation and management of software 367 and incorporate security measures that must be taken when a product reaches its 368 end of life. 369 o Perform secure program testing, review, and/or assessment to identify potential 370 flaws in codes and mitigate vulnerabilities. 371 o Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) 372 whenever an application or system undergoes a major change. 373 o Address security implications in the software acceptance phase including 374 completion criteria, risk acceptance and documentation, common criteria, and 375 methods of independent testing. 376 o Identify and prioritize mitigation and remediation of Common Vulnerability and 377 Exposure (CVEs) that have a high probability of being exploited on the Boundary 378 and Internal environments. 379

• Prepare reports that identify technical and procedural findings; Provide recommended 380 remediation strategies/solutions to Government ISSM and PM. 381

10.3.3 Risk Management Framework (RMF): 383

10.3.3.1 The contractor shall conduct cybersecurity services and support IAW DoD and MDA 385 policies for reporting and implementation for the authorization of enclaves, including 386 enforcement of policies, ensuring system compliance, A&A activities, cybersecurity tools, and 387 cybersecurity activities for Collateral and Program systems throughput the lifecycle of the 388 authorization. 389

Standards: 391

• Maintain a “ready state” for cybersecurity inspections, including the development of 392 compliant A&A documentation in coordination with ISSM on behalf of the system 393 owners (SOs); 394 o Appoint cybersecurity POC’s for each system to review and enforce the 395 alignment and compliance with DoD and Agency orders, directives, regulations 396 and instructions. 397 o Generate, collect and maintain data needed to meet system cybersecurity 398 reporting. 399 o Evaluate, validate, and implement security improvement actions. 400 o Review audit findings and ensure appropriate mitigation actions are taken. 401 o Coordinate cybersecurity inspections, tests, and reviews for the network 402 environment. 403 o Prepare, distribute and maintain plans, instructions, guidance, and standard 404 operating procedures concerning the security of network system(s) operations 405 throughout the lifecycle. 406 o Validate adherence to DoDs RMF strategy, ensuring all systems meet STIG and 407 SRG compliance. 408 o Create, update and upload documentation such as system diagrams, 409 hardware/software lists, CONOPS, and security to maintain a moderate or below 410 authorization IAW DoD and Agency defined timelines to system of record. 411 o Perform security reviews, identify gaps in security architecture, and update 412 security risk management plans annually. 413

• Develop, review and update repeatable processes, procedures, and templates to 414 standardize and streamline the development and delivery of A&A artifacts annually. 415

• Continuously validate the organization against policies, guidelines, procedures, 416 regulations and laws to ensure compliance. 417

• Update system security controls and A&A documentation based on the results of 418 continuous monitoring; 419 o Provide monthly reporting of cybersecurity program task status. 420 o Develop actionable plans for improving information security posture. 421

• Participate in Risk Governance process to provide security risks, mitigations, and input 422 on other technical risk. 423

• Oversee the implementation of policy standards and strategies to ensure procedures and 424 guidelines comply with cybersecurity policies. 425

• Develop repeatable processes, procedures, and templates to standardize and streamline 426 the development and delivery of RMF artifacts. 427

• Align security compliance processes and/or audits for external services (e.g., cloud 428 service providers, data centers) with DoD and agency requirements. 429

• Manage Information System Contingency Plans IAW NIST SP 800-34, Contingency 430 Planning Guide for Federal Information Systems; 431 o Ensure contingency plans (e.g., Continuity of Operations / Disaster Recovery 432 Plans) for information systems are developed, maintained and exercised/tested 433 and documented at least annually. 434

10.3.3.2 The contractor shall ensure system security is throughout the development lifecycle; 436 translates technology and environmental conditions (e.g., law and regulation) into security 437 designs and processes. 438 Standards: 440

• Participate in the development or modification of the computer environment 441 cybersecurity program plans and requirements; 442 o All acquisitions, procurements and outsourcing efforts address information 443 security requirements consistent with organization goals. 444 o Integrate Risk Management Framework process activities and related 445 documentation (e.g., system life-cycle support plans, concept of operations, 446 operational procedures, and maintenance training materials). 447 o Evaluate and identify security requirements specific to an information technology 448 (IT) system in all phases of the System Life Cycle. 449 o Document the implementation and functionality of security requirements and 450 appropriate information technology (IT) policies and procedures that are 451 consistent with Agency mission and goals. 452 o Provide cybersecurity guidance to SOs and data owners when assessing 453 categorizing information in accordance with Agency and Federal policies. 454 o Document and address organization’s information security, cybersecurity 455 architecture, and systems security engineering requirements throughout the 456 acquisition lifecycle. 457 o Ensure application of security patches for commercial products integrated into 458 system design meet the DISA mandated timelines for the intended operational 459 environment. 460

• Develop repeatable processes, procedures, and templates to standardize and streamline 461 the development and delivery of new IA enabled products and services. 462

• Align information security and/or cybersecurity policies to meet system analysis security 463 requirements. 464

• Align security compliance processes and/or audits for external services (e.g., cloud 465 service providers, data centers) with DoD and agency requirements. 466

• Provide OV1/SVI drawings that define system boundaries, system hardware/software 467 inventories, system interconnections, system responsible officials, and system users; 468 update system of record every 6 months. 469

10.3.4 Cybersecurity Project Integration: 471

10.3.4.1 The contractor shall design, develop, test, and evaluate information system security 473 throughout the systems development lifecycle. This includes assessment of current 474 environment(s) and identifying non-compliancy. 475 Standards: 477

• Analyze design constraints, analyze trade-offs and detailed system and security design, 478 and consider lifecycle support. 479

• Ensure all hardware/software to include products under development are authorized for 480 use. 481

• Design, develop, integrate, and update system security measures that provide 482 confidentiality, integrity, availability, authentication, and non-repudiation; 483 o Assess the effectiveness of cybersecurity measures utilized by system(s), identify 484 gaps, and document risk. 485 o Assess threats to and vulnerabilities of computer system(s) and develop a security 486 risk profile 487 o Conduct Privacy Impact Assessments (PIA) of the application’s security design 488 for the appropriate security controls, which protect the confidentiality and 489 integrity of Personally Identifiable Information (PII). 490 o Design or integrate appropriate data backup capabilities into overall system 491 design and ensure appropriate technical and procedural processes exist for secure 492 system backups and protected storage of backup data. 493

• Provide input to the Risk Management Framework process activities and related 494 documentation (e.g., system life-cycle support plans, concept of operations, operational 495 procedures, and maintenance training materials). 496

• Build, test, and modify product prototypes using working models or theoretical models. 497

• Develop Disaster Recovery and Continuity of Operations plans for systems under 498 development and ensure testing prior to systems entering a production environment. 499

• Develop and direct system testing and validation procedures and documentation. 500

• Develop detailed security design documentation for component and interface 501 specifications to support system design and development. 502

• Identify and direct the remediation of technical problems encountered during testing and 503 implementation of new systems (e.g., identify and find work arounds for communication 504 protocols that are not interoperable). 505

• Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever 506 an application or system undergoes a major change. 507

• Analyze user needs and requirements to plan and conduct system security development. 508

• Ensure security design and cybersecurity development activities are properly documented 509

(providing a functional description of security implementation) and updated as necessary. 510

• Implement and integrate system development life cycle (SDLC) methodologies into 511 development environment including employing configuration management processes. 512

• Design, implement, test, and evaluate secure interfaces between information systems, 513 physical systems, and/or embedded technologies. 514

• Develop cybersecurity designs to meet specific operational needs and environmental 515 factors (e.g., access controls, automated applications, networked operations, high 516 integrity and availability requirements, multilevel security/processing of multiple 517 classification levels, and processing Sensitive Compartmented Information). 518

• Develop security compliance processes and/or audits for external. 519

• 521

10.5 Control System Security Specialist (FRCS): (Severable – MS Filan) 525

10.5.1 The contractor shall perform device, equipment, and system-level cybersecurity 527 configuration and day-to-day security operations of control systems, including security 528 monitoring and maintenance along with stakeholder coordination to ensure the system and its 529 interconnections are secure in support of mission operations. 530 Standards: 532

• Perform the required cyberspace tasks required to obtain and maintain a low-moderate 533 risk for all the technology areas used within the control system. 534 o Maintain network segmentation to isolate control systems from business networks 535 and other external connections. 536 o Obtain approval from facility operations/engineer teams and IT or network 537 security teams before performing security related activities. 538 o Provide account management services; create, modify, lock, delete; audit and 539 report IAW MDA Policy 25. 540 o Conduct system maintenance, develop and update maintenance SOPs and 541 checklists, and maintain system maintenance records/logs. 542 o Implement STIGs and review/update quarterly. 543 o Conduct internal risk assessments of vulnerabilities and determine/implement 544 mitigation techniques to reduce risk to a moderate or low level. 545

• Update and maintain a lifecycle management plan within system of record annually; 546

Obtain ISSM approval before procurement or deployment of any IA enabled assets; 547

• Track all HW/SW; notify ISSM of HW/SW of end of life/end of support dates; provide a 548 plan of action to maintain system compliance to ISSM and PM every 6 months. 549

• Execute the cyber security program IAW with Federal executive orders, national security 550 directives, agency policies and other regulations to obtain and maintain a low-moderate 551 risk authorization; 552 o Update and maintain the MDA Risk Management Framework FRCS 553 authorizations. 554 o Apply approved organizational security policies and procedures to maintain 555 system security and ensure system availability. 556 o Off-load and review control system audit logs, identify anomalies and report to 557 ISSM weekly. 558 o Conduct quarterly STIG reviews and provide results to Government ISSM within 559 30 days; 560 o Document any deviations and submit to Government ISSM for approval. 561 o Review and update documentation that captures functions of security of control 562 system and IT technologies with which the control systems interface at least 563 annually. 564 o Establish and maintain security configuration baseline for the control system(s), 565 including field devices, IT components, interconnections, and interfaces. 566 o Perform risk self-assessments by reviewing and documenting the implementation 567 status of security requirements of control systems annually. 568 o Participate in control system incident and disaster response, including secure 569 system recovery; document results, capture lessons learned and provide to 570 Government ISSM annually. 571

• Perform asset management and maintain inventory of control system devices and 572 components through physical inspection or logical scans. 573 o Conduct weekly vulnerability scans, coordinate/implement remediation and 574 provide plan of action to ISSM for any open vulnerabilities. 575 o Apply updates, patches, and security technical implementation while maintaining 576 control system performance and availability requirements 577

• Participate in control system change management in conjunction with IT personnel and 578 control system experts (e.g., system supplier). Provide recommendations to ISSM and 579 document approved changes. 580

• Implement, respond, and report OPORDS, CTOs, FRAGOs, and other urgent MDA 581 Cybersecurity requirements IAW MDA CERT SLA. 582

• Mitigate/correct security deficiencies identified during security/certification testing 583 and/or recommend risk acceptance for the appropriate senior leader or authorized 584 representative within 45 days. 585

• Support execution of MDA CSSP-CERT Subscriber Deliverable Requirements 586 documented in the MDA/MS/CSSP SLA. 587

• Provide end user training on control system operations and maintenance. 588

• Integrated tracking and reporting of key indicators of risk (KIORS) for information 589 system security throughout the systems lifecycle. This includes assessment of current 590 environment(s) and identifying non-compliancy. 591

10. 6 Cyber Defense 594 The MDA Cyber Security Service Provider – Computer Emergency Response Team’s (CSSP-596 CERT) mission is to protect all MDA digital infrastructure and sensitive data from cyber threats 597 and attacks. The MDA CSSP-CERT employs a team of security analysts, engineers, and IT 598 professionals who work together to proactively detect, analyze, respond to, and mitigate security 599 incidents in real-time. The CSSP-CERT is located across two “Hot COOP” sites, with the 600 Colorado Springs, Colorado – MDIOC as the primary site and the Huntsville, Alabama – 601 Redstone Arsenal as the Hot COOP site. 602 HHQ for the scope of this task is defined as: 604

• JFHQ-DoDIN 605

• DISA 606

• DREN 607

• HPCMP 608

• DC3 609

• USSPACECOM 610

• USSTRATCOM 611

10.6.1 Cybersecurity Service Provider (CSSP) Command and Control (C2) Operations. The 613 contractor shall coordinate C2 operations for Cybersecurity activities and Defensive Cyber 614 Operations (DCO) across the agency. 615

Standards: 617

• Ensure personnel conducting C2 Operations capability are certified on the Cyber Defense 618

Analyst DCWF knowledge, skills, abilities, and tasks (KSATs) by Standards and 619 Evaluations. 620

• Continuously monitor Higher Headquarters (HHQ) information streams for relevant taskers and 621 Periods of Non-Disruption (POND) (DoDI 8530.01) 622

• Create and present to the Government MDA specific Cyber Tasking Orders (CTO) based on 623 HHQ direction No Later Than (NLT) one business day after notification from HHQ. Deliver 624 CTOs via the official system of record as documented in the MDA Cyber Incident Response Plan 625

(CIRP). (OPORD 8600-24) 626

• Interface with HHQs and subscribers to submit and/or respond to Requests for Information (RFI) 627 in order to gain required understanding of orders, taskers, or PONDs. (Agency Requirement) 628

• Monitor Period of Non-Disruption (POND) issuances posted by the MDA Global Network 629 Operations and Security Center (GNOSC) and present to the CSSP Government any degradation 630 of monitoring capabilities IAW CSSP 8009 Escalation Matrix (Agency Requirement) 631

• Coordinate all CSSP actions requiring MDA Work Screening Team (WST) approvals for flight 632 and ground test de-confliction. (Agency Requirement) 633

• Submit Significant Activity (SIGACT) / Red Reports IAW Government direction and/or as 634 required by CJCSI 6510.01B. 635

• Submit Operational Environment (OE) – Friendly Forces / Blue Reports IAW Government 636 direction and/or as required by JFHQ-DODIN OPORD 8600-24 Annex R or current version. 637

• Consolidate and present to the Government a singular Plan of Actions & Milestones (POA&M) 638 for all HHQ CTOs and taskers that will not be accomplished by the HHQ suspense. Submit as 639 drafts in the classified JFHQ-DoDIN POA&M repository no later than 2 business days prior to 640 the suspense date. (USCYBERCOM GENADMIN 17-0037) 641

• Notify all degradations or outages effecting the CSSPs capability to complete its Joint Mission 642 Essential Tasks within 1 hour of degradation or outage IAW an CSSP 8009 escalation matrix. 643 (DepSecDef Memorandum: Cybersecurity Service Provider Standardized Training and 644 Readiness) 645

• Integrate into the dashboard identified in para 10.2.5 of this document the following data: 646 o The status of all cybersecurity-related Command and Control (C2) between HHQ, Tier II 647

CSSP (Agency-level), Tier III MDA 2-Letter (2-Ltr) Local Control Centers (LCCs). 648 (DoDI 8530.01) 649 o The status of all active CTOs 650 o The status of all RFIs 651 o A dashboard displaying all systems under POND 652 o Any scheduled or ongoing activities requiring a WST 653 o The status of all SIGACTs and Blue Reports 654

10.6.2 24/7 DCO Detect Actions. Utilize cyber defense tools 24/7 to continuously monitor and 656 detect cyber threats within the MDA Area of Operations, and execute incident response activities 657 to mitigate the threat IAW DoDI 8530.01, CJCSM 6510.01B, the current Evaluators Scoring 658 Metric (ESM) and MDA CIRP. (DoDI 8530.01, CJCSM 6510.01) 659 Standards: 662

• Ensure personnel conducting DCO Detect Actions are certified on either Cyber Defense 663 Analyst and/or Cyber Defense Incident Responder DCWF KSATs by Standards and 664 Evaluations. 665

• Activate on-call Cyber Defense Incident Responders IAW CSSP 8009 the CSSP incident 666 escalation process. 667

• Characterize and analyze cyber security alerts to identify anomalous activity and 668 potential threats. 669

• Correlate vulnerability management data with network and endpoint security monitoring 670 to provide fewer false positives and a higher level of fidelity for incident detection, 671 handling, and countermeasures 672

• Coordinate with 2LTR cyber defense staff to validate cyber security alerts. 673

• Leverage intelligence provided by MDA Government to develop countermeasures across 674 cyber defense tools within 2 business days of receiving intelligence. (JMET OP 5.1.9) 675

• Create and present to the Government COAs to mitigate cyber events/vulnerabilities as 676 required by CJCSI 6510.01B and the MDA Cyber Incident Response Plan (CIRP). 677

• Report all degradations or loss of data feeds that impact greater than 10% of assets 678 monitored by the CSSP IAW CSSP 8009 escalation process NLT 1 hour after 679 degradation occurs. (Agency Requirement) 680

• Maintain a maximum of an eight hour mean time to respond to all cyber events identified 681 by CSSP DCO tools, IAW CJCSM 6510.01B. 682 o Mean time to respond is defined as the time from when an event is presented to 683 the analyst until the event has been documented in the government system of 684 record as a Category 8 “investigating” event IAW CJCSI 6510.01B. 685

• Execute the escalation process for any events that meet the criteria identified within 686 CSSP-CERT 8009 Escalation Process. 687

• Provide dedicated Cyber Defense Analyst support (in addition to standard support above) 688 ISO a combination of 4 Cyber Vulnerability Penetration Assessments (CVPAs) Cyber 689 Vulnerability Adversarial Assessments (CVAAs) and Cyber Penetration Testing 690 events/exercises per year. Each event will not exceed 7 calendar days of 24/7 support. 691 (DoDM 8530.01). 692 o Personnel supporting this standard will be operating in an “exercise environment” 693 and will not be available to conduct normal operations while supporting these 694 events. 695

• Develop, deliver, and maintain a real-time, continuous, automated reporting capability 696 that displays the log data as defined in the “MDA CSSP Logging Requirements.xlsx” 697 provided in the bidder’s library. 698 o This capability may be integrated into the dashboard identified in para 10.2.5 of 699 this document but is not required to be. 700

10.6.3 Vulnerability Management Analysis. The contractor shall conduct open-source 702 vulnerability research and establish correlation processes utilizing subscriber provided asset data 703 to identify exploits or threat actor opportunities. 704 Standards: 706

• Ensure personnel conducting Vulnerability Management Analysis are certified on the 707 Vulnerability Assessment Analyst DCWF KSATs by Standards and Evaluations. 708

• Integrate into the dashboard identified in para 10.2.5 of this document the following data: 709 o A view for each MDA accredited system identifying: 710

Total number of endpoints 711

Number of endpoints that have reported all information required by OPORD 712 20-0020 or current guidance 713

The number of endpoints configured IAW the published MDA toolset 714 configuration 715

An average vulnerability score for each authorized system as defined by the 716 current version of the Command Cyber Readiness Inspection (CCRI) 717

The top five most common vulnerabilities on the accredited system 718 Trending data for all requirements above going back 6 months 719 o A view that aggregates all asset and vulnerability information and correlates that 720 information with cyber threat intelligence information received through 721 intelligence community channels within the DoD 722 o 723

• Operate and maintain an MDA specific Vulnerability Management program in accordance with 724

JFHQ-DoDIN OPORD 20-0020 or current DoD Vulnerability Management guidance. (CDRL: 725 DI-MISC-80508B, Technical Report—Study/Services) 726

• Draft a Standard Operating Procedure that identifies required vulnerability scanning 727 configurations for all MDA endpoints IAW OPORD 20-0020 or current guidance. Deliver to 728 subscribers in order to help them properly configure their toolsets to meet DoD requirements. 729

10.6.4 Forensic Analysis. The contractor shall conduct forensic analysis of any cyber events 731 meeting the CJCSI 6510.01B criteria of a category 1, 2, 4, or High 7. 732 Standards: 734

• Ensure personnel conducting Forensic Analysis are certified on the Cyber Defense 735 Forensic Analyst DCWF KSATs by Standards and Evaluations. 736

• Acquire, preserve, and document copies of digital media, logs, and investigative technical 737 data associated with cyber intrusion incidents and investigations in accordance with 738 organization/law enforcement documented chain of custody procedures; 739

• Using predefined agreements and TTPs with the ISSO and/or ISSM to notify the DoD 740 LE/CI agencies responsible for the affected portion of the DODIN of cyber mission 741 forces (CMF) deployment, and any LE/CI support requested; 742

• Initiate and/or support coordination planning between users, security personnel, LE, CI, 743 vendors, Internet service providers, cloud service providers, other CSSPs and other 744 internal or external security components; 745

• Assist law enforcement officials with information gathering for LE/CI investigations and 746 cyber incidents by collecting and retaining specified information on all incidents in 747 support of LE investigations, and/or situational awareness in accordance with established 748 organizational/LE/CI guidance; 749

• Ensure the acquisition and preservation of copies of digital media, logs, and investigative 750 and technical data associated with cyber intrusion incidents, investigations, and 751 operations required for tactical analysis, strategic analysis, or law enforcement 752 investigations are in accordance with established organizational/LE/CI chain of custody 753 protocols; 754

• Provide secure artifacts and evidence collection and analysis to forensics investigators in 755 accordance with established organizational/LE/CI chain of custody protocols of the 756 recipient’s organization; 757

• Implement and enforce procedures to prevent unauthorized disclosure of investigative 758 information; 759

• Retain and secure all incident reports and collected information for one year; 760

• Provide regular and recurring updates through all phases of the incident handling 761 lifecycle, as identified in policies, procedures, orders, or collaboration requirements; 762

• Conduct incident close out activities as authorized or directed once coordinated response 763 actions have been completed by external partner and supported agencies; and 764

• Conduct post incident after action review with the AO, ISSM, and LE officials, at a 765 minimum to identify lessons learned. 766

• Perform no more than three digital forensic analysis cases concurrently, which can be in 767 any combination of cyber incident response and mitigation, digital forensics analysis in 768 support of root cause identification, reverse malware engineering support and cyber 769 exercise support. Conclude all forensic investigations with a forensics examination report 770 IAW Forensic Report Template(DoDI 8531.01) 771

10.6.5 CSSP Governance and Technical Writing. The contractor shall develop and deliver to 773 the government technical documents required for CSSP operations. 774 Standards: 776

• Ensure personnel conducting CSSP Governance and Technical Writing are certified on 777 the Knowledge Manager DCWF KSATs by Standards and Evaluations. 778

• Update and maintain the MDA Cyber Incident Response Plan (CIRP) IAW DOD 779 5220.22-M-SUP-1. (CDRL: xxxx from TO8800) 780

• Update and maintain the CSSP Service Level Agreement (SLA) for each subscriber 781 aligned to the CSSP IAW DoDI 8530.01. (CDRL: xxxx From TO8800) 782

• Update and track both provider and subscriber compliance with requirements in the SLA 783 and report this compliance to CSSP Chief and Director of Cyberspace Mission Support 784 quarterly. Maintain and track this data for a minimum of three years. 785

• Conduct trend analysis on subscriber/provider compliance data and identify ongoing 786 Limiting Factors (LIMFACS) and potential issues with the SLA responsibilities. (DoDI 787 8530.01) 788

• Deliver no more than three “2-Ltr Cybersecurity Briefs” per month, which will update 789 information outlined in the template provided in the DD1423 790

• Review and edit all documentation presented to the Government and/or subscribers for 791 style, grammar, purpose, and audience in accordance with DoD Plain Language standards 792 as defined in https://www.esd.whs.mil/dd/plainlanguage/ 793

10.6.6 Quality Assurance (QA) and Inspection Support. The contractor shall conduct self-795 inspections and QA of activities supporting the CSSP. 796 Standards: 798

• Ensure personnel conducting Quality Assurance and Inspection Support are certified on 799 the IT Program Auditor DCWF KSATs by Standards and Evaluations. 800

• Ensure the CSSP-CERT is in inspection order at all times; inspections include limited 801 notice/no notice cyber inspections, Evaluators Scoring Metric (ESM), Command Cyber 802 https://www.esd.whs.mil/dd/plainlanguage/

Readiness Inspection (CCRI), Inspector General (IG) and Internal Review (IR) 803 inspections. 804

• Communicate instances where the CSSP-CERT is not in inspection compliance to the 805 Government via the TOSR. (Executive Order 13800) 806

• Conduct and deliver to the Government CSSP Chief no later than 30 calendar days after 807 the assessment, the results of an annual Agency specific ESM self-assessment, utilizing 808 the most current grading documentation published the ESM inspector’s office. (Agency 809 Requirement) 810

• Provide Subject Matter Experts to act as primary POCs during DoD inspections for any 811 functions that are not inherently Government. (Agency Requirement) 812

• Lead the CSSP Lessons Learned (LL) program IAW CJCSI 3150.25H by conducting 813 monthly lessons learn forums, incorporating LL into current cyber incident response 814 strategy no later than 30 days after the LL forum where they are identified, sharing LL 815 via Joint Lessons Learned Information System (JLLIS) and/or other appropriate means, 816…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .