CMPP_Cyber_Security_Requirements_Appendix_CV3.docx

DOCX document 33 KB Posted

Attached to
Award Notice - Central Meat Processing Plant Federal contract opportunity
Solicitation number
HQC007-17-Q-0023
Issued by
Defense Commissary Agency

About this file

Appendix C - Cyber Security Requirements

View the file

Other files for this federal contract opportunity

Other files attached to Award Notice - Central Meat Processing Plant, newest first.
File Type Posted
CMPP_PWS_V5.FBO_rev1.pdf PDF
HQC007-17-Q-0023-0006.FBO.pdf PDF
CMPP_Technical_Requirements_-_Appendix_BV4_FBO-Rev2.pdf PDF
HQC007-17-Q-0023-0005.FBO.pdf PDF
CMPP_Technical_Requirements_-_Appendix_BV4.FBO-Rev1.pdf PDF
HQC007-17-Q-0023-0004.FBO.pdf PDF
HQC007-17-Q-0023-0003.FBO.pdf PDF
HQC007-17-Q-0023-0002.FBO.pdf PDF
HQC007-17-Q-0023-0001.FBO.pdf PDF
HQC007-17-Q-0023.FBO.pdf PDF
HQC007-17-Q-0023_draft_8.3.17.pdf PDF
CMPP_Technical_Requirements_-_Appendix_BV3.docx DOCX document
CMPP_Functional_Requirements_Appendix_AV3.docx DOCX document
CMPP_Telecommunications__Requirements_Appendix_DV3.docx DOCX document
CMPP_PWS_V3.docx DOCX document
Show all 15

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Appendix CCybersecurity RequirementsC-2
C.1Authorization RequirementsC-2
C.2U.S. DoD Personnel Security RequirementsC-2
C.3Information Assurance Workforce Improvement ProgramC-3
C.4Public Key Infrastructure (PKI) or Smart Card RequirementsC-3
C.5PKE/PKI Compliance RequirementsC-3
C.6User IdentificationC-4
C.7Audit LogsC-5
C.8DoD STIG ComplianceC-5
C.9Cybersecurity Mitigation StrategiesC-5
C.10DoD Information Assurance Vulnerability AlertsC-5
C.11Security TestingC-6
C.12Integration & Testing EnvironmentsC-6
C.13Disposing of Electronic Media.C-6

Cybersecurity Requirements Authorization Requirements The work in this PWS will be sensitive but unclassified. The contractor shall comply with all applicable DoD security regulations (including those to protect information that is designated Personally Identifiable Information (PII)) and procedures during the performance of this contract. The contractor shall not disclose and must safeguard procurement sensitive information, computer systems and data, Privacy Act data, and Government work products that are obtained or generated in the performance of this contract. This includes dissemination of protocols and papers not generally available through the public literature.

Cybersecurity and U.S. DoD security requirements include the following:

1. Assessment & Authorization (A&A)

1. Compliance with the RMF DoD Instruction 8510.01 and National Institute of Standards and Technology (NIST) 800-53 security controls for an unclassified system with a System Categorization Level not to exceed Confidentiality Rating of Low, Integrity Rating of High, and Availability Rating of High.

1. Generation of all required documentation to support the initial RMF “Interim Authority to Operate” and “Authority to Operate”

1. Compliance with all Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs)

1. Use of Public Key Infrastructure (PKI) for authentication and use of DoD PKI certificate services and DeCA’s active directory capability to authenticate Common Access Card (CAC) users

1. Security procedures to allow system access only to authorized users

1. Restriction of users’ access to only authorized functions and data

1. Audit logs that track system changes by user are captured, stored and forwarded for review

1. Digitally signed Category I mobile code using DoD-approved PKI code-signing

1. Limited access to web servers by Transport Layer Security (TLS) or strong cryptography for connections over secure Hypertext Transfer Protocol Secure (HTTPS)

1. Compliance with Information Assurance Vulnerability Alerts (IAVAs) within the time frame required

The contractor shall ensure compliance of Department of Defense Contract Security Classification Specification, DD Form 254, as included with this PWS.

U.S. DoD Personnel Security Requirements Contractor personnel shall comply with DoD and DeCA security policies and procedures as part of their daily interface with DeCA. The contractor shall not divulge any information about files, data, processing activities or functions, user IDs, passwords, or other knowledge that may be gained, to anyone who is not authorized access to such information. The contractor will ensure all employees with access to such information sign a nondisclosure agreement furnished by DeCA immediately following contract award. The contractor shall adhere to Cybersecurity policies and procedures as defined in DoD and DeCA directives, instructions, and regulations.

The CMPP business system will have a System Categorization that will determine the U.S. DoD Cybersecurity requirements for hardware and software systems as defined in DoD Instruction (DoDI) 8500. The contractor shall have a Cybersecurity program that meets or exceeds the requirements defined in DoDI 8500.01 and NIST 800-53.

Information Assurance Workforce Improvement Program The Contractor shall be in compliance with DoD 8570.01-M "Information Assurance Workforce Improvement Program," which requires contractor staff to meet the baseline certification requirement prior to beginning work on this contract: http://www.dtic.mil/whs/directives/corres/pdf/857001p.pdf. The baseline certification requirement applies to all system administrators/privileged users performing cybersecurity functions as defined by DoD 8570.01-M. In addition, system administrators/privileged users are required to obtain the additional qualifications for their position within 6 months of engagement. Proof of compliance will be furnished to the COR.

Public Key Infrastructure (PKI) or Smart Card Requirements Workstations connected to the DeCA domain will be required to meet future Public Key Infrastructure (PKI) and smart card requirements. Specifically, all CMPP workstations that require or provide a means for users to authenticate to the DeCA domain or access network resources (i.e., email, web, etc.), outside the CMPP application, must be equipped with DoD-approved smart card readers and middleware capable of reading DoD/DeCA smart cards (i.e., Common Access Card (CAC)) and Federal smart cards following the FIPS 201 standard. When possible, smart card readers and middleware must follow the DeCA standard. The CMPP contractor must also configure these workstations with DeCA standard workstation settings to support DeCA’s implementation of smart card logon for the domain and use of public key services.

All personnel with access to the DeCA domain shall obtain a DoD Common Access Card (CAC). DeCA contractors working on-site at DoD/DeCA facilities or at non-DoD/DeCA facilities using Government Furnished Equipment (GFE) shall obtain their PKI certificate from the DoD PKI. DeCA’s VPN currently requires PKI for authentication using smart card authentication via the CAC. VPN users will be required to obtain DoD CAC for access.

Contractors working at non-DoD facilities without access to DeCA’s domain but with a need for PKI to exchange information securely with DeCA counterparts (e.g., email or web related), shall obtain certificates from a DoD authorized External Certification Authority (ECA). Certificate issuance and revocation are managed in accordance with the ECA Certificate Policy. Approved ECAs may be found at http://iase.disa.mil/pki/eca/Pages/index.aspx.

PKE/PKI Compliance Requirements Since DeCA cannot predict the CMPP configurations that vendors may propose, DeCA provides the following guidance relative to DeCA Public Key Enabling (PKE) requirements using the DoD public key infrastructure (PKI) and the common access card (CAC):

Network and server side authentication, within the CMPP environment, based on public key technology will use DoD-approved PKIs for this service, in accordance with DoD Cybersecurity Discipline Implementation Plan.

All DoD private Web servers accessing the CMPP system shall use TLS/HTTPS; HTTP is not authorized. A private Web server is one that a user must authenticate to gain browser access. The DoD Chief Information Officer (DOD CIO) requires all internal websites use PKI for authentication unless the DeCA CIO approves the use of an assertion service. DeCA reports PKI compliance to the DoD CIO monthly.

Additionally, for Private Web Servers providing access to sensitive information:

If web server functionality:

is embedded in the CMPP COTS application, resides within the CMPP environment, serves no other applications other than CMPP and, has unused ports blocked.

Then no additional client-side PKE is required provided that the embedded web server ports are blocked from WAN access.

If the proposed CMPP solution complies with the guidance cited above, Then DeCA will not require CMPP vendor to modify its CMPP application to incorporate use of CAC authentication. Within the CMPP application, CMPP shall rely on user IDs and complex passwords for authentication purposes.

Else CMPP private web servers providing access to sensitive information shall be configured for client authentication using DoD-approved certificates and CMPP applications residing behind web servers requiring authorization based on individual identity shall use the identity provided by certificate-based authentication to support access control decisions (per DoDI 8520.2).

For specialized equipment, including but not limited to wired and wireless equipment interfaces, scales, management consoles, HHTs, etc.

If all of the following are true for the device:

No keyboard, mouse, or touch screen provides navigation outside the CMPP application.

No end user has access to the operating system, or Root/System Administrator functions.

No network login or access to network resources outside the CMPP environment.

No other navigation is possible outside CMPP applications, e.g., CAO, DIBS/EBS.

Then no PKE is required for the device.

Else the specialized equipment shall be configured to use DoD-approved certificates for user identification and authentication.

All DoD e-mail systems are required to support sending and receiving e-mail signed and encrypted using approved certificates. If the CMPP system is to process e-mail, it must meet this requirement.

If offerors have questions related to the PKE requirements for CMPP, they should raise these questions through the contracting office for resolution with the DeCA Cybersecurity staff. Proposal responses should indicate if the proposed CMPP solution supports CAC-based authentication or Light- weight Directory Access Protocol without extensive modification.

User Identification The CMPP system shall include procedures to restrict system access to authorized users by using CAC, logins, passwords, and multiple levels of authorization by category, group, and individual users. It shall also restrict users to only authorized functions and data.

· All CMPP system processes shall be user-id driven so all production steps can be tracked back to the originator.

· The CMPP system shall provide user security within the applications that allow users to be setup with defined roles based on job duties.

· CMPP devices, for example, those with alphanumeric keyboards that provide direct user access to other network or CMPP services outside the meat plant, web browsing to other Internet or Intranet sites, or access to an application outside the meat plant, must additionally and first provide network authentication before they provide CMPP system authentication.

· These options shall also be provided for wireless hand- held terminals, mobile devices and other emerging technologies.

Strong passwords are required and must meet the following standards:

· As supported by the device: 15 characters or more

· Must include at least one lowercase character, one uppercase character, one special character, and one number

· Must not allow the reuse of the last eight passwords

· Must expire passwords every 60 days and require the user to change it.

· Must lock accounts after three failed login attempts.

Audit Logs The CMPP system shall generate and maintain audit logs that track changes by user that can be remotely retrieved. It shall have the capability for recording when (date and time) data are created, updated, or deleted. It shall also provide the capability for system administrators (SAs) to implement audits to identify: who (user or program) updated pricing data, and the date and time. The audit logs must be available for a year and easily retrievable for analysis.

DoD STIG Compliance The CMPP system shall comply with all applicable DoD Security Technical Implementation Guide (STIG) guidance. A DoD reference document, such as a STIG or security requirements guide, constitutes the primary source for security configuration or implementation guidance for the deployment of newly acquired systems. STIGs are available for operating systems, databases and generic web based applications, network devices, storage devices, software, etc. STIGS are available online at: http://iase.disa.mil/stigs/Pages/index.aspx.

Cybersecurity Mitigation Strategies Cybersecurity mitigation strategies include security updates, service packs, and changes to operating procedures, when physical and cyber vulnerabilities are detected. Operating system, routers, servers, development platforms and the application being delivered to the Government shall be in compliance with all known applicable Department of Defense Computer Emergency Response Team (DoD-CERT) Alert, Bulletin, Technical Advisory Notices, and Common Vulnerabilities and Exposures (CVEs) published during the past 36 months. The contractor shall comply with all Cyber Command and JFHQ-DODIN task orders as directed by DeCA.

Ports, protocols, and services management: The CMPP implementation shall comply with the latest available DoD ports, protocols, and services guidelines delineated in DoDI 8551.01 and the Ports, Protocols, and Services Assurance Category Assignments List (CAL). The CMPP contractor shall disable all unused ports, services, and protocols. The CMPP contractor shall color code for risk any ports, protocols, and services (PPS) used within CMPP and designated by DoD PPS guidance. The green PPS are considered best security practices and recommended for use in CMPP when implemented.

The system shall comply with DoD requirements for the installation and configuration of DoD's Host Based Security System (HBSS) point products including McAfee Agent (MA), McAfee Virus Scan Enterprise (VSE), Host Intrusion Prevention System (HIPS), Asset Baseline Monitor (ABM), Asset Configuration Compliance Module (ACCM), Policy Auditor (PA), and Data Control Module (DCM).

DoD Information Assurance Vulnerability Alerts The contractor shall implement an information assurance vulnerability management (IAVM) program for the CMPP system. The DoD IAVM program provides electronic security protections against known threats and vulnerabilities. The IAVM program requires the registration of information system assets, which allows for the timely dissemination of critical vulnerability information. It assists in the documentation and tracking of compliance, providing increased electronic security to DeCA systems.

The DeCA Cybersecurity staff shall provide the CMPP contractor with each relevant Information Assurance Vulnerability Alert (IAVA). The CMPP contractor shall ensure that the CMPP system complies with DoD IAVAs within the timeframe required by the IAVA documentation and report compliance to the DeCA Program Manager and DeCA Cybersecurity staff. Guidance regarding the requirement for IAVM is contained in DeCAM 35-31.1, Information Assurance Vulnerability Management Manual, December 15, 2009 and Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01 (Appendix A to Enclosure B), July 10, 2012, provides additional reference information. In addition DeCA’s enterprise vulnerability scanners and compliance scanners shall be used to validate compliance with the IAVM program and ensure remediation of all CVEs.

Security Testing The CMPP application will be submitted to vulnerability testing and the DoD Assessment & Authorization (A&A) process. CMPP shall achieve authorization before DeCA deploys the system. DoDI 8510.01 provides the current DoD requirements and methodology that DeCA will use to conduct the assessment and authorization (A&A) of CMPP; the DoD A&A guidance is subject to change as part of the DoD effort to streamline the assessment and authorization process. CMPP shall comply with the security controls for an unclassified system with a System Categorization Level not to exceed Confidentiality Rating of Low, Integrity Rating of High, and Availability Rating of High. DeCA shall conduct a Security Test and Evaluation (ST&E) for the security controls as directed in NIST 800-53 during the CMPP A&A effort. The CMPP contractor shall assist DeCA in the generation of all required documentation to support the DoD Risk Management Framework (RMF) “Approval to Operate” (ATO) before CMPP production deployment. In addition, the contractor shall perform all mitigation required for authorization. The telecommunications networks and systems introduced as part of CMPP shall meet requirements of the Defense Information Systems Agency (DISA) STIGs for network infrastructure, network security, Web Services, wireless connectivity, platforms, and applications. The contractor will support the annual test and review of security controls as well as all re-authorization efforts.

Integration & Testing Environments The contractor shall maintain integration/test environments in accordance with Cybersecurity best practices and operational requirements. During product integration, the contractor shall ensure that all Cybersecurity mitigation strategies have been applied to the integration environment, and an Interim Authority to Test (IATT) obtained from the Authorizing Official (AO), at a minimum, prior to any Government data being loaded onto any assets or software interacting with the production environment for testing or delivery.

Disposing of Electronic Media.

The contractor shall follow DoD standards and procedures, and use approved products to dispose of unclassified hard drives and other electronic media, as appropriate, in accordance with DoDI 8500. The contractor shall follow DoD guidance on sanitization of other internal and external media components in DoDI 8500.01, DoDI 5000.64, and NIST SP 800-88, “Guidelines for Media Sanitization”.

C-6

File details come from the government source that posted it. Updated .