Assessment_and_Authorization_Support_Draft_SOW.pdf
PDF 884 KB Posted
- Attached to
- FEMA INFORMATION TECHNOLOGY INDUSTRY DAY Federal contract opportunity
- Solicitation number
- HSFE30-15-S-0001
View the file
Other files for this federal contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PROCUREMENT SENSITIVE
Assessment & Authorization Support
INTENTIONALLY LEFT BLANK
ii
Table of Contents
1.0 Introduction
1.1 Scope
1.2 Background/Current Contract Environment
1.3 Objectives
1.4 Applicable Documents
2.0 Specific Tasks
2.1 Task 1 - Project Management
2.1.1 Background
2.1.2 Clearance Requirement
2.1.3 Mission/Objectives/Goals
2.2 Task 2 - Agent of the Certifying Authority/Risk Executor Support Services
2.2.1 Background
2.2.2 Clearance Requirement
2.2.3 Mission/Objectives/Goals
2.3 Task 3 - Documentation Management, Policy, Guidance and Publication Support... 10
2.3.1 Background
2.3.2 Clearance Requirement
2.3.3 Mission/Operations/Goals
2.3.4 Deliverables
2.3.5 Contractor Experience Requirements – Key Personnel
2.4 Task 4 - Audit and Assurance Services
2.4.1 Background
2.4.2 Clearance Requirement
2.4.3 Mission/Operations/Goals
2.5 Task 5 - Security Awareness, Training and Education Services
2.5.1 Background
2.5.2 Clearance Requirement
2.5.3 Mission/Operations/Goals
2.5.4 Contractor Experience Requirements – Key Personnel
i
2.6 Task 6 - System/Application Vulnerability and Penetration Testing Support (Internal and External)
2.6.1 Background
2.6.2 Clearance Requirement
2.6.3 Mission/Operations/Goals
2.7 Task 7 - A&A Support (Security Independent Verification and Validation)
2.7.1 Background
2.7.2 Clearance Requirement
2.7.3 Mission/Operations/Goals
2.8 Task 8 - A&A Support (Cyber Security Resiliency)
2.8.1 Background
2.8.2 Clearance Requirement
2.8.3 Mission/Operations/Goals
2.8.4 Deliverables
2.9 Task 9 – Adhoc and Surge Requirements
2.9.1 Background
2.9.2 Clearance Requirement
2.9.3 Mission/Operations/Goals
3.0 Deliverables
4.0 Place of Performance
4.1 Project Management
4.2 Technical Writer Support
4.3 Document Management, Policy, Guidance, and Publication Support
4.4 Audit and Assurance Services
4.5 Security Awareness, Training and Education Services
4.6 System/Application Vulnerability and Penetration Testing Services
4.7 A&A Support (Security Independent Verification and Validation)
4.8 A&A Support (Cyber Security Resiliency)
5.0 Certifications
6.0 Government Furnished Information
7.0 Government Furnished Equipment (GFE)
8.0 Security Requirements
8.1 Access to Classified and Sensitive but Unclassified (SBU) Information ii
8.2 Employment Eligibility
8.3 Continued Eligibility
8.4 Suitability Determination
8.5 Background Investigations
8.6 Security Management
8.6.1 Information Technology Security Clearance
8.6.2 Information Technology Security Training and Oversight
9.0 Section 508 Compliance
9.1 Section 508 Applicable EIT Accessibility Standards
9.2 Section 508 Applicable Exceptions
9.3 Section 508 Compliance Requirements
10.0 Other Considerations
10.1 Travel Requirements
10.2 Inspection and Acceptance
10.3 Operating Constraints
Appenix A. Performance Based Matrix iii
INTENTIONALLY LEFT BLANK
iv
1.0 INTRODUCTION
FEMA’s Chief Information System Officer (CISO) and staff is responsible for developing a comprehensive management approach for ensuring compliance with the Federal legislation, regulation and guidelines, departmental policies and procedures as well as ensuring systems operate at an acceptable risk. The CISO is Division Chief for the Office of Cyber Security (OCS) and reports directly to the FEMA Chief Information Officer (CIO). OCS functions as FEMA’s principal office for cyber security management, oversight, and issue resolution. The oversees FEMA’s Cyber Security Program by managing and controlling all aspects of security vulnerabilities, including conducting incident investigation, diagnosis, resolution, recovery, and closure, as well as establishing and maintaining security education and training programs.
OCS will utilize this contract vehicle for Cyber Security staff augmentation, services, and support
• Project Management provides project management services for OCS tasks and activities
• 24x7 Security Operations Center (SOC) Services that support Response Team, Detection
Team, Protection Team, Sensor Support Team, Advance Technology Team (modernization tools/research lab), and Cyber Intelligence (Threat Management).
• Certification Agent/Risk Executor Support the will perform Assessment and Authorization (A&A) Package Reviews, briefing to the Chief Information Officer (CIO)/Authorizing Official, and Chief Information Security Officers, prepare and finalized for signature and submission, and recommend authorization decisions.
• Policy, Guidance and Publication Support develops Cyber Security-related policies and procedures. In addition, provides customized security-specific brochures and publications.
• Audit and Assurance Services provides qualified cyber security professional to assist with the remediation of internal and external audit findings.
• Security Awareness, Training and Education Services which includes basic and advanced security training and workshops to be offered every quarter, customized security awareness programs, annual Cyber Security Awareness month activities, a comprehensive Cyber Security web site, security-specific brochures and publications, and many other awareness and compliance programs.
• System/Application Vulnerability and Penetration Testing Support (Internal and External) perform infrastructure, application, network, database, and mobile vulnerability services as well as Secure Code Reviews on FEMA information systems. In consort, utilize the latest tools and techniques to simulate the way a hacker or disgruntled employee might use gain-unauthorized access to an information system.
• Regional Support (Threat Management) provides services to Regional Offices concentrating on threat intelligence information and operational support.
• A&A Support (Security Independent Verification and Validation) will provide an Independent Verification and Validation (IV&V) of a management, operational, and technical security controls on a system to determine if the controls were properly implemented in support of initial, reauthorization, and continuous security accreditation.
• A&A Support (Cyber Security Resiliency) will provide accurate identification, documentation, and testing of security controls.
• Adhoc and Surge Requirement provide responses to OCS adhoc cyber security requests.
The Offeror shall provide experienced certified security professionals to serve as ISSOs over various FEMA systems.
1.1 Scope
Provide the expertise, technical knowledge, staff support, and other related resources necessary to:
• Perform analysis to ensure security controls are consistently implemented.
• Integrate new technology with Cyber Security standards.
• Develop and execute plans for monitoring, assessing, and verifying security controls across all major information systems.
• Develop, evaluate, and exercise IT survivability and contingency plans.
1.2 Background/Current Contract Environment
OCS provides cyber support to FEMA’s emergency management and continuity mission by utilizing the Federal Cyber Security Framework, in order to
• Identify risks to systems, assets, data, and capabilities;
• Protect mission essential and critical services;
• Detect cybersecurity events;
• Respond to detected cybersecurity events; and
• Recover capabilities or services that were impaired due to a cybersecurity event.
OCS plans, coordinates, integrates, synchronizes, and conducts activities that lead day-to-day safeguarding and protection of FEMA information systems (directly and indirectly connected to the FEMA infrastructure). At a minimum, OCS supports information within the continental United States (CONUS) and outside the continental United States (OCONUS). These systems may reside at the FEMA Headquarter within the National Capital Region; the 10 Regional Offices; 8 Distribution Centers, and the various Disaster Emergency Communications facilities.
The Top Technology challenges are face by OCS are:
1. Resiliency – Resilient Architecture and Operations
2. Automated Risk Detection-monitoring Heuristic/Behavioral - Large scale/Real-time/Multi-domain
3. Automated Risk Mitigation
4. Usability – Transparent Security http://en.wiktionary.org/wiki/continental_United_States
5. Cloud - Store Sensitive Government Data Searchable and Usable on Public Clouds
6. Detection and Response Mechanisms for Insiders (Timely, Fine-grained)
7. Leverage Classified Knowledge/Signatures in a Host-based System
8. Mobility - Hardware RoT, SEAndroid, Secure boot, Secure Baseband
9. Security for Cloud User Environments – Thick/Thin Client, Virtualization
10. Engineering, Testing, and Operating Secure Composite Systems
11. Establishing and Maintaining Assurance in Heterogeneous, Mobile and Cloud
Environments
FEMA’s mission is to reduce the loss of life and property and protect communities nationwide from all hazards, including natural disasters, acts of terrorism, and other manmade disasters.
FEMA leads and supports the nation in a risk-based, comprehensive emergency management system of preparedness, response, recovery, assistance, and mitigation. In support of this mission, FEMA uses a wide variety of information systems and IT solutions and services. These systems, solutions, and services must be operated and maintained at the highest level of confidentiality, availability, and integrity.
OCS will provide oversight and management of the work and tasks orders under this Statement of Work. The mission of the FEMA OCIO is “to enhance and maintain IT infrastructure; develop and enhance key systems to support operating programs; increase efficiencies and cooperation across FEMA’s divisional and regional lines.” The vision and strategy of the OCIO is to modernize FEMA IT systems and services and to “deliver world-class secure IT guidance, products, and services to meet the needs of FEMA’s emergency managers and stakeholders nationwide.” The environment must be implemented with the flexibility required to support the evolving mission of FEMA and to support the surge requirements necessary to support emergency situations as they occur.
Currently, FEMA’s IT environment is an amalgam of new and legacy technologies, architectures, platforms, and tools that includes a wide variety of PC-based, client-server, web-based and service-oriented components. The IT systems supporting FEMA’s mission has been implemented by using a variety of service providers under both mature and immature oversight and governance conditions. As stated above, the current goals are to continue the evolution and improvement of all IT services and support. The OCIO goal will be achieved by utilizing an approach and strategy that is consistent with both the Department and Agency strategy.
1.3 Objectives
The following are objectives of the FEMA Cyber Security Program:
• Perform gap analysis on current security infrastructure
• Ensure consistent application of information security standards across all agency information systems.
• Meet all regulatory and agency documented standards and guidance.
• Integrate these regulations and standards into a fully implementable security program.
• Ensure preparation for internal and external audits through management of all infrastructure artifacts required to pass audits.
• Ensure all new information technology (IT) projects meet or integrate security standards into their development.
• Develop a culture of security-mindful professionals across the community.
• Strive to be more flexible and responsive to new regulatory directives.
• Serve as the central authority for all Cyber Security-related activities across the agency.
• Ensure information system survivability and integrity.
• Optimize processes to meet Cyber Security-related goals and strategies
1.4 Applicable Documents
• National Institute of Standards and Technology (NIST), Special Publication (SP) 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems— A Security Life Cycle Approach, February 2010
• NIST SP 800-39, Managing Information Security Risk—Organization, Mission, and Information System View, March 2011
• NIST SP 500-53, Security and Privacy Controls for Federal Information Systems and Organizations
• NIST SP 500-53, Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans
• NIST SP 800-65, Integrating Cyber Security into the Capital Planning and Investment Control Process, dated January 2005
• 4300A Sensitive Systems Policy -- Version 11.0
• 4300A Sensitive Systems Policy Handbook -- Version 9.1 o Attachment B - Waivers Request Form -- Version 11 o Attachment C - ISSO Letter -- Version 11 o Attachment D - Type Accreditation -- Version 11 o Attachment E - FISMA Reporting -- Version11 o Attachment F - Incident Response -- Version 9.1 o Attachment G - Rules of Behavior -- Version 11 o Attachment H - POAM Process Guide -- UNDER REVISIONS -- Version 9.1 o Attachment I - Workstation Logon o Attachment K - IT Contingency Plan Template -- Version 11 o Attachment L - Password Management o Attachment M - 800-53 Controls -- Version11 o Attachment N - Interconnection Security Agreements -- Version 11 o Attachment O - Vulnerability Management -- Version 9.1 o Attachment P - Document Change Requests -- Version 11 o Attachment Q1 - Wireless Systems --Version 11 o Attachment Q2 - Mobile Devices -- Version 11 o Attachment Q3 - Tactical Systems o Attachment Q4 - RFID Systems -- Version 11 o Attachment R - Compliance Framework Guide -- Version 9.1 http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Policy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Handbook.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20B%5d%20Waiver%20Request%20Form.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20C%5d%20ISSO%20Letter.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20D%5d%20%20Type%20Accreditation.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20E%5d%20FISMA%20Reporting.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20F%5dIncident%20Response.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20G%5d%20%20Rules%20of%20Behavior.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20H%5dPOAM%20Guide.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20I%5dWorkstation%20Logon.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20K%5d%20%20IT%20Contingency%20Plan%20Template.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20L%5dPassword%20Management.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20M%5d%20Tailoring%20NIST%20800-53%20Security%20Ctrls.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20N%5d%20Interconnection%20Security%20Agreements.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20O%5dVulnerability%20Management.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20P%5d%20Document%20Change%20Requests.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q1%5d%20Sensitive%20Wireless%20Systems.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q2%5d%20Mobile%20Devices-CLEAN%20DRAFT.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q3%5dTactical%20Systems.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q4%5d%20Sensitive%20RFID%20Systems.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20R%5dCompli%20Fmwk%20CFO-designated%20Systems.pdf o Attachment S - Compliance Framework for Privacy Systems -- UNDER REVISIONS -- Version 9.1 o Attachment S1 - Managing CREs containing SPII -- UNDER REVISIONS -- Version 9.1 o Attachment T - Acronyms o Attachment X - Social Media -- UNDER REVISIONS
• 4300B National Security System Policy Cover Page - Version 9.0
• 4300B National Security Systems Table of Contents - Version 9.0
• 4300B.100: Safeguarding and Risk Management for NSS
• 4300B.101 Risk Management for NSS
• 4300B.102 National Security System Security Control Guidance
• 4300B.103 Template Guidance o 4300B.103-1 Template for System Security Plans o 4300B.103-2 Template for Risk Assessment Reports o 4300B.103-3 Template for Security Assessment Reports o 4300B.103-4 Template for Plans of Action and Milestones
• 4300B.106 DHS NSS General and Privilege User Account Request Minimum Requirements
• 4300B.107 Decommissioning Strategy Minimum Requirements
• 4300B.108-1 National Security System References
• 4300B.108-2 National Security System Policy Change Request
• 4300B.200 Communication Security (COMSEC) - Version 2.0
• DHS Ongoing Authorization Methodology
• DHS CISO NIST SP 800-53 Security Controls tri-fold
• DHS FISMA System Inventory Methodology
• DHS Information Security Performance Plan
• DHS Security Authorization Process Guide
• DHS Document Review Methodology
• Document Review Checklists
• Security Authorization Document Templates
• FIPS-199 Workbook and Instructions
• Privacy Threshold Analysis (PTA) Template
2.0 SPECIFIC TASKS
2.1 Task 1 - Project Management
2.1.1 Background
A project is a temporary group activity designed to produce a unique product, service or result.
A tasks and activities executed within the OCS are treated as projects. Contractor shall provide project management services for OCS tasks and activities. Project Management services shall adhere to the PMI Project Management framework for project planning, scheduling, http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20S%5dCompliance%20Framework%20for%20Privacy%20Systems.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20S1%5dManaging%20CREs%20Containing%20SPII.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20T%5dAcronyms.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.000%20National%20Security%20Systems%20Policy%20Coverpage.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.000_TOC_4300B_05102013.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.100%20-%20Safeguarding%20and%20Risk%20Mgmt%20for%20NSS.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.100%20-%20Safeguarding%20and%20Risk%20Mgmt%20for%20NSS.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.101%20-%20Risk%20Management%20Framework.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.101%20-%20Risk%20Management%20Framework.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.102%20-%20NSS%20Security%20Control%20Guidance%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.102%20-%20NSS%20Security%20Control%20Guidance%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-1%20-%20System%20Security%20Plans%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-1%20-%20System%20Security%20Plans%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103.2%20-%20Risk%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103.2%20-%20Risk%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-3%20-%20Security%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-3%20-%20Security%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-4%20-%20Plans%20of%20Action%20and%20Milestones.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-4%20-%20Plans%20of%20Action%20and%20Milestones.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.107%20-%20Decommissioning%20Strategy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.107%20-%20Decommissioning%20Strategy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.108-1%20-%20NSS%20References.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.108.2%20-%20NSS%20Policy%20Change%20Request.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.200%20COMSEC.pdf communications, reporting, and contractual activity and to ensure that any technical issues are addressed quickly and professionally.
2.1.2 Clearance Requirement
All personnel supporting this task must have a SECRET clearance and adhere to guidance outline within Section 8.0 of this document.
2.1.3 Mission/Objectives/Goals
The Offeror’s Project Manager shall be responsible for the Project Planning and Project Management aspects of this task. This task continues for the entire duration of the project.
This task includes the regularly scheduled meetings and specified documentation; i.e., Weekly Status Meeting, Weekly Status Reports, Weekly Work, Plan Review, Schedule Review, and Oversight/Stakeholder Reporting.
The Offeror shall develop a Program Management Plan (PMP) for the successful execution of the tasks within this SOW. The PMP shall include, as a minimum:
• Statement of Objectives (SOO)
• Chart of organizational relationships, authority, and responsibilities
• Plan of Actions and Milestones (POA&M)
• Time-phased budget for cost control
• Project Risk Identification
• A requirements document
• A continuity of business plan detailing certification processes and practices to aid in the event of a change of contractors
Work products such as Weekly Activity Reports, Monthly Activity Reports, Program Status Reports, and meetings shall be included in the PMP.
The Offeror shall develop a Project Plan to manage, schedule, and track progress using Microsoft (MS) Project. The current progress information shall be provided to the Government through contractor management meetings, monthly activity reports, and MS Project files.
• Provide leadership, management, and administrative support for contractor work in support of Cyber Operations. Specific activities include but are not limited to the following:
• Provide overall management and oversight of contract staff and activities to ensure all work comply with applicable Department and OCIO policies and regulations; ensure contractor performance is timely and meets OCIO/CISO program goals and performance standards
• Provide overall technical leadership and oversight; recommend and oversee the implementation of proactive and leading edge technical and technological approaches and solutions to address emerging cyber security trends; report on an annual basis
• Provide administrative support for contract work activities to include support Cyber Operations; prepare memorandums and correspondence; perform filing, passing of clearances, meeting and conference coordination, and other office administration duties
• Provide and finalize the Program Management Plan within 20 business days of contract start date.
• Provide and finalize individual Task Management Plan that addresses at a minimum, performance schedule, milestones, deliverables, and approaches to problem resolution and communication and coordination with Government personnel within 20 business days of contract start
• Provide and finalize GFE Inventory Management Procedures within 20 business days of contract start
• Monitor and track program and task performance to ensure on time service delivery within established cost estimates
• Identify, recommend, and implement (upon Government approval) cost-saving measures
• Provide monthly Task Status Report for each task (to the designated Government Technical Monitor) by the 15th of each month, presenting:
o Activities and milestones completed and deliverables submitted for each task for the past month o Indication of potential schedule variance, mitigation strategies, and actions taken o Issues encountered and resolution applied o Issues unresolved and current status and actions o Milestones and activities planned for the next reporting period
• Provide monthly Program Status Report (to the Contracting Officer’s Representative) by the 15th of each month, incorporating the Task Status Reports and the following for the overall program:
o Total cost incurred in the past month and fiscal year-to-date o Indication of potential cost and/or schedule variance, mitigation strategies, and actions taken o Funding and expenditure status o Staffing status to include current staffing level (%); positions open/unfilled and number of days open/unfilled o Cost saving measures implementation status including activities and milestones completed and planned
• Conduct Program and individual Task Status Review monthly, as requested by the
Program Manager and/or COR, to provide opportunity for report clarification and issue resolution
• Prepare and conduct quarterly Program Performance Reviews (IAW Quality Assurance Surveillance Plan) to include identification of potential cost saving measures in each task area and related implementation plans and status
• Support acquisition of materials and services incidental to contractor work activities
The Offeror shall submit a written Monthly Activity and Program Status Reports, to include but not limited to:
• A summary of accomplishments for the month which includes ,
• Updated of the SOW Plan of Action and Milestones (POA&M) schedule (originally delivered as part of the PMP) including milestones achieved and schedule changes
• Funding expended and funding remaining
• A copy of deliverables submitted to the government for acceptance,
• Program risks identified and mitigation action taken and planned
• A narrative of management or technical problems,
• Suggestions and Recommendations, and
• A projected schedule for next month’s activities
The Offeror shall develop and submit the following management controls reports:
• Contract Management Meetings,
• Use of Automated Tools
• Quality Control (QC) and Quality Assurance (QA) Procedures
The Offeror shall provide consulting services for this task to the government.
2.1.3.1 Regular Contractor Management Meetings
The Offeror and FEMA shall hold regularly scheduled monthly Contractor Management Meetings. The meeting shall provide the government and the Offeror an opportunity to discuss current tasking, provide additional guidance to the technical task management of the contract, and give the Offeror an opportunity to ask questions pertinent to the successful completion of the task.
2.1.3.2 Quality Control and Quality Assurance Procedures
Quality of data is paramount importance to the FEMA. The Offeror plays a critical role in establishing and maintaining the quality of the program. The Offeror shall perform the following:
• Data Collection Quality Control (QC) – The Offeror shall develop and implement a written QC program for data collection to ensure compliance with DHS and FEMA processes and procedures.
• Data Quality Assurance (QA) – The Offeror shall support and participate in the DHS QA review program as defined by the requirements of Contractors QA Procedures. The Offeror shall provide propose corrective actions to the COR to address any minor deficiencies identified in the review within five working days of receiving the QA report.
If the Offeror receives an unacceptable QA rating, FEMA may suspend the Offeror’s activities, by written notice from the Contracting Officer (CO) until acceptable adjustments have been implemented and an acceptable QA is earned by the Offeror.
The Offeror shall report all activities during travel, in a format specified by the Contracting Officer’s Representative (COR).
2.2 Task 2 - Agent of the Certifying Authority/Risk Executor Support Services
2.2.1 Background
OCS serves as an Agent of the Certification Authority (ACA) that performs validation services under the NIST that includes approximately twenty-five (25) on-site assessments annually, across both CONUS (80%) and OCONUS (20%) sites, and twenty-five (25) annual remote assessments. Both on-site and remote assessments include validations under the NIST/DHS Security Authorization and site assistance visits to prepare CNDSP customers for triennial Command Cyber Readiness Inspections (CCRI) from the Defense Information Systems Agency (DISA). The current projection of growth for the OCS Security Authorization program is that it is expected to double in size over the next three years. These auditors will also play a key role by providing feedback to developers for incorporation into the OCS outreach program, a new OSS program that will consolidate information assurance checklists and reduce a duplication of efforts and improve inspection efficiency through electronic communication.
2.2.2 Clearance Requirement
All personnel supporting this task must have a TOP SECRET/SCI clearance and adhere to guidance outline within Section 8.0 of this document.
2.2.3 Mission/Objectives/Goals
The Offeror shall provide support services for those customers seeking assistance in obtaining authority to operate. Capabilities include both testing and validating functions of implemented s controls, functions that may potentially overlap with existing ISSM/ISSO personnel functions assigned to Information Systems (ISs).
Agent of the Certifying Authority (ACA) /Risk Executor Support Services with ISSM/ISSO functions seeking an authority independent of the program to perform both testing and validating of any existing IS security controls put in place by the IS developers. If mitigations to remaining IS vulnerabilities are required, the ACA possesses the necessary skills to recommend additional security controls for program personnel to implement so that the ACA could subsequently re-test and validate.
ACA support without ISSM/ISSO functions seeking an authority independent of the program to perform validation of security controls implemented and tested by ISSM/ISSO personnel before the OVS can certify the IS for accreditation at the appropriate Authorizing Official (AO).
The Offeror shall provide a Cyber Operations and Service Manual to update, test, implement and validate the most efficient and effective methods for conducting Cyber Vulnerability Assessments
The OCS program is responsible for ensuring compatibility and compliance with the DHS and FEMA’s Cyber Security Programs outlined in [INSERT SECTION NUMBER] for all OCS operational network systems located across the US. Knowledge and extensive experience in networking, systems management, programming and tool development, the UNIX (primarily LINUX and SOLARIS) operating system, the Microsoft Windows (all variants) operating system, security analyst tools and techniques, and data base design and management is necessary to identify required modifications and determine innovative solutions.
The Offeror shall provide the Cyber Security with accreditation and certification requirements for the OCS Enterprise.
The Offeror shall provide a Cyber Operations and Service Manual to update, test, implement and validate efficient and effective methods for managing an Information Assurance program while providing 24x7 Cyber Network analysis services. The Offeror shall be expected to identify issues within operational systems in regard to Cyber Security and suggest procedures to optimize network activity.
2.3 Task 3 - Documentation Management, Policy, Guidance and Publication Support
2.3.1 Background
2.3.2 Clearance Requirement
All personnel supporting this task must have a TOP SECRET clearance and adhere to guidance outline within Section 8.0 of this document.
2.3.3 Mission/Operations/Goals
The Offeror shall establish, maintain, and administer an integrated data management system for collection, control, publishing, and delivery of all program documents. The data management system shall include but not be limited to the following types of documents:
CDRLs, White Papers, Status Reports, Audit Reports, Agendas, Presentation Materials, Minutes, Contract Letters, and Task Order Proposals. The Offeror shall provide the Government with electronic access to this data, including access to printable reports.
The Offeror shall develop new security documentation as required by the Government and maintain existing NIST/DHS Security Authorization -required documentation for each AMC all information systems programs. Each of the programs identified in Appendix 1 are at different phases in the security life cycle; therefore, the security documentation status of each program is also at various stages.
The Offeror shall request, gather and formalize inputs to various NIST/DHS Security Authorization -required documentation from other organizations (i.e. program management offices, system management offices, system administrators, functional managers, etc.) to fully complete all NIST/DHS Security Authorization requirements.
The Offeror shall complete or assist in the coordination of all NIST/DHS Security Authorization -required documentation for each system prior to a program’s submission for an Authorization to Operate (ATO) and an Authorization to Connect (ATC). The Offeror will monitor the status of the NIST/DHS Security Authorization package through the ATO/ATC phases and will keep the ISSM abreast of current status.
The Offeror shall accomplish updates to maintain the currency of each program’s security documentation. Each security document must always reflect the most current status of the associated information system, which may require daily or weekly updates.
The Offeror shall provide Program Certification Status Reports by the 15th calendar day of each month. The reports must be organized by program. The reports will include (1) most current certification dates for each server and network device, (2) system accreditation expiration date,
(3) most current dates and types of Authorization to Operate (ATO(s)), as well as expiration dates, (4) most current dates and types of Authorization to Connect (ATC(s)), as well as expiration dates, and (5) explanation for any expired ATOs and/or ATCs.
The Offeror shall provide a Plan of Action and Milestones (POA&M) Report by the 1st calendar day of each month identifying all POA&M items that are due within the next 60 days.
• Evaluate and recommend an enterprise-wide security document management solution and methodology. If implemented, support and maintain the document management solution.
• Provide expert analysis of new federal guidance and/or changes to the security environment as it impacts security documentation.
• Support and maintain the confidentiality, integrity, and availability of security documentation.
• Optimize the content and usability of policy- and procedure-related security documentation
• Perform annual review and recommend updates of the Manual 6680 policy section
• Perform annual review and recommend updates of up to 125 enterprise-wide OCS procedures within 11 months of last government approval date
• Perform periodic testing and evaluation of the effectiveness of information security policies, procedures, practices, and security controls to be performed with a frequency depending on risk, but no less than annually
2.3.3.1 Records, Files, and Documents
All physical records, files, documents, and work papers, provided and/or generated by the Government and/or generated for the Government in performance of this SOW, maintained by the Offeror which are to be transferred or released to the Government or successor contractor, shall become and remain Government property and shall be maintained and disposed of Records Disposition – Procedures and Responsibilities; the Federal Acquisition Regulation,.
Nothing in this section alters the rights of the Government or the Offeror with respect to patents, data rights, copyrights, or any other intellectual property or proprietary information as set forth in any other part of this SOW or the Application Services contract of which this SOW is a part (including all clauses that are or shall be included or incorporated by reference into that contract).
2.3.4 Deliverables
2.3.5 Contractor Experience Requirements – Key Personnel
2.4 Task 4 - Audit and Assurance Services
2.4.1 Background
2.4.2 Clearance Requirement
All personnel supporting this task must have a TOP SECRET/SCI clearance and adhere to guidance outline within Section 8.0 of this document.
2.4.3 Mission/Operations/Goals
The Offeror shall perform independent validation of OCFO information systems following generally accepted audit protocols to ensure full compliance to FISMA, FISCAM, and A-123 requirements. The audit work shall remain separate of the other tasks to ensure segregation of duties and independence. The Offeror shall record findings into IACS as an independent validator. The Offeror shall support OCFO OFS during the annual Office of Inspector General (OIG) audits for FISMA and/or FISCAM. The Offeror shall support OFS A-123 internal review and audit program as well. The Offeror shall record findings for other sources such FedRAMP, SSAE16, or OIG into the IACS tool. The Offeror for this task shall be certified information system auditor with substantial experience in IT compliance auditing. The Offerors shall support the OFS Director for Performance Management and Quality Assurance for this task.
2.5 Task 5 - Security Awareness, Training and Education Services
2.5.1 Background
Cyber Security shall perform a Security Awareness Analysis of the OCS Training Program using current DHS, FEMA, NIST, and industry best practice standards. The results of the security training shall be delivered to the government within a formal report.
After the security awareness results are delivered to government, Cyber Security shall work at the direction of the government to develop comprehensive security training course (to include training material) and provide advance information security training as required for FEMA designated personnel with significant OCS responsibility such as:
• Information System Security Manager
• Information System Security Officer
• Network/System Administrators
• Web/Database Administrators.
2.5.2 Clearance Requirement
All personnel supporting this task must have a TOP SECRET clearance and adhere to guidance outline within Section 8.0 of this document.
2.5.3 Mission/Operations/Goals
Cyber Security shall deliver all work products of this task on DVD or CD to the COR, CISO or OCS designee.
The Offeror shall provide certification training to be ordered through task orders awarded under this contract. Current certification training to include:
COMPTCyber Security
A+ Network+ Security+ Advanced Security Practitioner (CASP) A+ Continuing Education (CE) Security+ Continuing Education (CE) Network+ Continuing Education (CE) Advanced Security Practitioner Continuing Education (CE)
ISC2 Certified Information System Security Professional (CISSP) Certified Authorization Official (CAP) Systems Security Certified Practitioner (SSCP) Information Systems Security Management Professional (CISSP-ISSMP) Information System Security Architecture Professional (ISAP) Information System Security Engineering Professional (ISSEP) Information System Security Management Professional (ISSMP)
EC Council Certified Ethical Hacker (CEH) ISACA Certified Information Security Manager (CISM)
Certified Information Systems Auditor (CISA) GIAC GIAC Certified Incident Handler (GCIH)
GIAC Security Leadership (GSLC) N/A GIAC Security Essentials (GSEC)
GIAC Certified Intrusion Analyst (GCCyber Security) GIAC Certified Enterprise Defender (GCED) GIAC System and Network Auditor (GSNA)
2.5.4 Contractor Experience Requirements – Key Personnel
2.6 Task 6 - System/Application Vulnerability and Penetration Testing Support (Internal and External)
2.6.1 Background
2.6.2 Clearance Requirement
guidance outline within Section 8.0 of this document.
2.6.3 Mission/Operations/Goals
This optional task provides the ability to increase the Tier 1 and/or Tier 2 capability to meet changes and expansion to the mission requirements. Specifically, this task provides the ability to perform analyses and studies to implement or integrate new capabilities or enhance existing processes and procedures to meet emerging MIRD requirements or improve operational efficiency. Specific activities include but are not limited to the following:
• Evaluate, test, recommend, integrate, implement, and/or support new methods, techniques, technologies, and products to improve operational efficiency and/or enable enhanced capabilities for FEMA SOC/EDCIRC, IV&V and Vulnerability Management to include capabilities for performing web and database scanning and scanning of other IT assets, monitoring and trend analysis of attempted external attacks, and protection of Personal Identifiable Information (PII)
• Contribute technical expertise in the development and implementation of the modernized, state- of-the-art IT infrastructure, and implementation of enterprise-wide protection capabilities and safeguards
• Interact and coordinate security monitoring and network defense and protection activities with other organizations and Department entities to support compliance with new and emerging national security and homeland security requirements
• Provide monthly project status report as part of the MIRD Task Status Report by the 15th of each month, containing details as described in paragraph 7.2, Program Management and Administration
• Report on quality performance measures quarterly as part of the overall Program performance review
This task will have multiple incremental increases in capacity, above the baseline identified in previous tasks, allowing the Government the flexibility to meet the mission requirements.
If/when executed the period of performance will be from the date of the contract action to the end of the current base period of performance and then will be rolled into the following baseline option.
At least annually, conduct perimeter network vulnerability scans
• Analyze scan results and coordinate with Cyber Security Operations staff to assist in identifying mitigation strategies
• Conduct a minimum of one complete penetration test for all Department networks and outsourced capabilities
• Interface and coordinate with third party organizations performing penetration testing and vulnerability scanning for the Department
• Interface and coordinate with the OCIO information Assurances Services Directorate to establish targets for testing, test schedule, test goals, and rules of engagement supporting System Accreditation activities
• Plan and coordinate White Cell participation in support of each specific penetration test
• Work with Department Legal for clearance on attack plans and rules of engagement
• Perform penetration testing, complying with NIST SP 800-115; produce reports and conduct management briefings on test activities, scenarios, results and recommendations
• Stay abreast of current attack vectors and unique methods for exploitation of computer networks.
• Develop unique exploit code and attack vectors to conduct penetration tests
• Render expertise and guidance to other cyber security programs regarding intrusion methods
• Provide monthly project status report as part of the MIRD Task Status Report by the 15th of each month,
• Report on quality performance measures quarterly as part of the overall Program performance measures review
The Offeror shall provide consulting services for this task to the government.
2.7 Task 7 - A&A Support (Security Independent Verification and Validation)
2.7.1 Background
2.7.2 Clearance Requirement
All personnel supporting this task must have a TOP SECRET/SCI clearance and adhere to guidance outline within Section 8.0 of this document.
2.7.3 Mission/Operations/Goals
Contractor shall verify the results and perform an assessment of raw scan data. Verification of results shall consist of a method of test, raw scan results, and a findings presentation (see also, paragraph INSERT SECTION HERE).
Contractor shall deliver in a POA&M-formatted document (CDRL AXXX) the STIG and Cyber Security non-compliant technical findings identified by comparing the security baseline to security hardening guides, United States Cyber Command (USCYBERCOM) Cyber Securitas, compliance testing (whether conducted internally or by independent organizations such as the ASCA), and project-specific system scan data. This project-specific document shall list mitigations and milestones with completion dates, and serve to track the resolution of project-specific vulnerabilities identified during the development process. When the project is completed and accepted for operational use, the system POA&M shall be updated based on changes the project made to the system security posture and the supporting body of evidence shall either be loaded into VMS or maintained in current format for tracking and resolution.
2.8 Task 8 - A&A Support (Cyber Security Resiliency)
2.8.1 Background
2.8.2 Clearance Requirement
guidance outline within Section 8.0 of this document.
2.8.3 Mission/Operations/Goals
The Offeror shall assist the FEMA Chief Information Officer and Chief Information Security Officer support and provide scheduling, planning, penetration testing/auditing and reporting services on FEMA applications, systems, networks and data centers. The Offeror shall assist the Government in providing information security assessments and authorization activities required by FISMA and Special Publication 800-37 latest version. The system security officer and A&A activities shall include reviewing system boundaries, completing and/or updating system security plans, network diagrams, hardware asset and software inventories (to include system inventories), and contingency plans, performing security assessments to include vulnerability scanning and secure configuration testing using Government approved tools (e.g., Tenable Security Center, NESSUS, HP Web Inspect, performing onsite evaluations of IT configurations and documenting assessment steps, results, and risks. The Offeror may be required to work with other federal employees and contractors throughout the performance of this task.
Specifically, the Offeror will be asked to interface with contractor’s supporting FEMA’s portfolio management, technology spend, enterprise architecture, and capital planning and investment control activities.
A&A support emphasis is on accurate identification, documentation, and testing of security controls for system assessments scheduled during the period of performance. The Offeror shall perform security control assessments based on Special Publication 800-53 (the latest version) and SP 800-53A, including technical vulnerability scanning and secure configuration assessments, penetration testing, web vulnerability scanning, and analysis of results. Security assessment shall be documented within Security Assessment Plans, vulnerability scan analysis, Security Assessment Reports, and Plans of Actions and Milestones (POA&Ms). The culmination of each assessment shall be documented for FEMA Authorizing Officials, Authorizing Official Designated Representative, within the Security Assessment Report, which shall include a summary of system assessment activities, and Risk Assessment table documenting risks to the system and detailing risks to be accepted as well as those requiring POA&Ms.
Information System Owner/System Security Officers support emphasis is on accurately identifying assets and risks (threat/likelihood/impact) to the system, working closely with developers and system administrators to provide guidance on secure IT implementation, performing maintenance, and ensuring consistency across security documents, providing assurance that the level of risk and risk acceptance are commensurate with the controls that are implemented or should be implemented on the system, conducting security impact reviews of information technology acquisitions, and ensuring security control descriptions and stated residual risks are comprehensive and understood by the information system owner.
All activities shall be based on criteria outlined in the latest version of NIST Federal Information Processing Standards and Special Publications: SP800-18, SP800-37, SP800-53, SP800-53A, SP800-60, FIPS-199, FIPS-201, and FIPS-140-2.
2.8.4 Deliverables
The Offeror may be responsible for part or all of the security documentation, in accordance with DHS A&A templates, developed in accordance with the NIST Special Publications that will be provided by FEMA, for each Statement of Work during the performance of this contract.
This required security documentation shall include at all or a portion of the following:
• Initial Resource loaded schedule submitted within 30 days following the completion of the proof of concept review at a single FEMA site, to include a Work Break Down Structure (WBS) to at least the fourth level with a Data Dictionary
• Penetration Test/Audit Plan shall be submitted to the government for written approval within 5 days prior to conducting a Penetration Test/Audit for the designated site visit.
• Security Assessment Report or executive summary of the security testing activities, description of identified risks, and plans of actions and milestones.
• System Security Plan includes a description of the system, accreditation boundary, and applicable security controls.
• System Diagram to include network diagrams depicting physical and virtual architecture of systems to include interconnection agreements with other IT investments.
• Systems inventory or a one-stop resource for discovering information about the information resources owned or operated by a FEMA organization or site.
• Software inventory or a list…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .