Emerging_Technology_and_Modernization_Support_Draft_SOW.pdf

PDF 775 KB Posted

Attached to
FEMA INFORMATION TECHNOLOGY INDUSTRY DAY Federal contract opportunity
Solicitation number
HSFE30-15-S-0001
Issued by
Federal Emergency Management Agency Mitigation Section

View the file

Other files for this federal contract opportunity

Other files attached to FEMA INFORMATION TECHNOLOGY INDUSTRY DAY, newest first.
File Type Posted
FBO15.pdf PDF
FBO13_(002).pdf PDF
FBO12.pdf PDF
FBO11.pdf PDF
FBO10.pdf PDF
FBO9.pdf PDF
FBO8a.pdf PDF
FBO7replacement_(003).pdf PDF
FBO7_2272017.pdf PDF
FBO6_12202016.pdf PDF
FBO5b_(003).pdf PDF
FBO3_8APR16.pdf PDF
PWS6d-Emerging_Technology_and_Modernization_Support_v5.pdf PDF
PWS6a-Information_System_Security_Officer_v5.pdf PDF
PWSAPPLICATIONENGINEERING.pdf PDF
PWSOperations_and_Maintenance.pdf PDF
FBO.pdf PDF
PWS6c-Security_Operations_Center_Support_v5.pdf PDF
PWS6b-Assessment_and_Authorization_Support_v5.pdf PDF
ITOCIrevised5_(3).pdf PDF
OCISecurity5.pdf PDF
IT_Security.pdf PDF
Application_Development.pdf PDF
Mission_Needs.pdf PDF
QAIVV.pdf PDF
Hardware.pdf PDF
General_or_No_Category.pdf PDF
Program_Management_Oversight.pdf PDF
IT_Industry_Day_Roster_-_December_05_2014.pdf PDF
FEMA_IT_Industry_Day_Final_141205.pdf PDF
FEMA_BPA_Draft__Version_12__4__2014_(3).pdf PDF
Security_Operations_Center_Support.pdf PDF
Information_System_Security_Officer_Draft_SOW.pdf PDF
FEMA_BPA_Hardware_Software_Draft.pdf PDF
REQUIREMENTS _ESTIMATES _AND_SCOPE_(RES).pdf PDF
Assessment_and_Authorization_Support_Draft_SOW.pdf PDF
O__M_-_DRAFT_SOW_09102014.pdf PDF
PMO_Contract_SOO-Draft_(2).pdf PDF
Application_Development_Engineering_and_Sustainment_Draft_SOW.pdf PDF
OCIO_Procurement_Diagram.pdf PDF
FEMA_Information_Technology_Industry_Day_Agenda.pdf PDF
FlyerIndustryDay.pdf PDF
Phased_Contract_Award_Approach_Flyer.pdf PDF
Socioeconomic_Disadvantage_Concerns_Flyer.pdf PDF
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PROCUREMENT SENSITIVE

Emerging Technology and Modernization Support

Statement of Work

INTENTIONALLY LEFT BLANK

ii

Table of Contents

1.0 Introduction

1.1 Scope

1.2 Background/Current Contract Environment

1.3 Objectives

1.4 Applicable Documents

2.0 Specific Tasks

2.1 Task 1 - Project Management

2.1.1 Background

2.1.2 Clearance Requirement

2.1.3 Mission/Objectives/Goals

2.2 Task 2 - Senior Technical Writer Support

2.2.1 Background

2.2.2 Clearance Requirement

2.2.3 Mission/Objectives/Goals

2.3 Task 3 - Security Engineering Support

2.3.1 Background

2.3.2 Clearance Requirement

2.3.3 Mission/Operations/Goals

2.4 Task 4 - Emerging Technology and Modernization Support

2.4.1 Background

2.4.2 Clearance Requirement

2.4.3 Mission/Operations/Goals

2.4.4 Tools Infrastructure Operational Support

2.4.5 Procurement of Hardware, Software, and Services

3.0 Deliverables

4.0 Place of Performance

4.1 Project Management

4.2 Technical Writer Support

4.3 Emerging Cyber Technology

i

4.4 Security Engineering Support

4.5 Emerging Technology and Modernization Support

5.0 Certifications

6.0 Government Furnished Information

7.0 Government Furnished Equipment (GFE)

8.0 Security Requirements

8.1 Access to Classified and Sensitive but Unclassified (SBU) Information

8.2 Employment Eligibility

8.3 Continued Eligibility

8.4 Suitability Determination

8.5 Background Investigations

8.6 Security Management

8.6.1 Information Technology Security Clearance

8.6.2 Information Technology Security Training and Oversight

9.0 Section 508 Compliance

9.1 Section 508 Applicable EIT Accessibility Standards

9.2 Section 508 Applicable Exceptions

9.3 Section 508 Compliance Requirements

10.0 Other Considerations

10.1 Travel Requirements

10.2 Inspection and Acceptance

10.3 Operating Constraints

Appenix A. Performance Based Matrix ii iii

1.0 INTRODUCTION

FEMA’s Chief Information System Officer (CISO) and staff is responsible for developing a comprehensive management approach for ensuring compliance with the Federal legislation, regulation and guidelines, departmental policies and procedures as well as ensuring systems operate at an acceptable risk. The CISO is Division Chief for the Office of Cyber Security (OCS) and reports directly to the FEMA Chief Information Officer (CIO). OCS functions as FEMA’s principal office for cyber security management, oversight, and issue resolution. The oversees FEMA’s Cyber Security Program by managing and controlling all aspects of security vulnerabilities, including conducting incident investigation, diagnosis, resolution, recovery, and closure, as well as establishing and maintaining security education and training programs.

OCS will utilize this contract vehicle for Cyber Security staff augmentation, services, and support

• Project Management provides project management services for OCS tasks and activities

• Security Engineering Support provides full Security Engineering life cycle support. This includes the development of security requirements, architecture and security designs, product analysis and recommendations, implementation support, to include acceptance testing, and incremental functionality testing.

• Emerging Technology and Modernization Support will provide FEMA service that broker the development of processes and modernization of the conventional technology. The service will allow for Laboratory research that solves complex problems in areas of computer science, information technology, communications, networking, and socio-technical systems

The Offeror shall provide experienced certified security professionals to serve as ISSOs over various FEMA systems.

1.1 Scope

Provide the expertise, technical knowledge, staff support, and other related resources necessary to:

• Perform analysis to ensure security controls are consistently implemented.

• Integrate new technology with Cyber Security standards.

• Develop and execute plans for monitoring, assessing, and verifying security controls across all major information systems.

• Develop, evaluate, and exercise IT survivability and contingency plans.

1.2 Background/Current Contract Environment

OCS provides cyber support to FEMA’s emergency management and continuity mission by utilizing the Federal Cyber Security Framework, in order to

• Identify risks to systems, assets, data, and capabilities;

• Protect mission essential and critical services;

• Detect cybersecurity events;

• Respond to detected cybersecurity events; and

• Recover capabilities or services that were impaired due to a cybersecurity event.

OCS plans, coordinates, integrates, synchronizes, and conducts activities that lead day-to-day safeguarding and protection of FEMA information systems (directly and indirectly connected to the FEMA infrastructure). At a minimum, OCS supports information within the continental United States (CONUS) and outside the continental United States (OCONUS). These systems may reside at the FEMA Headquarter within the National Capital Region; the 10 Regional Offices; 8 Distribution Centers, and the various Disaster Emergency Communications facilities.

The Top Technology challenges are face by OCS are:

1. Resiliency – Resilient Architecture and Operations

2. Automated Risk Detection-monitoring Heuristic/Behavioral - Large scale/Real-time/Multi-domain

3. Automated Risk Mitigation

4. Usability – Transparent Security

5. Cloud - Store Sensitive Government Data Searchable and Usable on Public Clouds

6. Detection and Response Mechanisms for Insiders (Timely, Fine-grained)

7. Leverage Classified Knowledge/Signatures in a Host-based System

8. Mobility - Hardware RoT, SEAndroid, Secure boot, Secure Baseband

9. Security for Cloud User Environments – Thick/Thin Client, Virtualization

10. Engineering, Testing, and Operating Secure Composite Systems

11. Establishing and Maintaining Assurance in Heterogeneous, Mobile and Cloud

Environments

FEMA’s mission is to reduce the loss of life and property and protect communities nationwide from all hazards, including natural disasters, acts of terrorism, and other manmade disasters.

FEMA leads and supports the nation in a risk-based, comprehensive emergency management system of preparedness, response, recovery, assistance, and mitigation. In support of this mission, FEMA uses a wide variety of information systems and IT solutions and services. These systems, solutions, and services must be operated and maintained at the highest level of confidentiality, availability, and integrity.

OCS will provide oversight and management of the work and tasks orders under this Statement of Work. The mission of the FEMA OCIO is “to enhance and maintain IT infrastructure; develop and enhance key systems to support operating programs; increase efficiencies and cooperation across FEMA’s divisional and regional lines.” The vision and strategy of the OCIO is to modernize FEMA IT systems and services and to “deliver world-class secure IT guidance, products, and services to meet the needs of FEMA’s emergency managers and stakeholders http://en.wiktionary.org/wiki/continental_United_States nationwide.” The environment must be implemented with the flexibility required to support the evolving mission of FEMA and to support the surge requirements necessary to support emergency situations as they occur.

Currently, FEMA’s IT environment is an amalgam of new and legacy technologies, architectures, platforms, and tools that includes a wide variety of PC-based, client-server, web-based and service-oriented components. The IT systems supporting FEMA’s mission has been implemented by using a variety of service providers under both mature and immature oversight and governance conditions. As stated above, the current goals are to continue the evolution and improvement of all IT services and support. The OCIO goal will be achieved by utilizing an approach and strategy that is consistent with both the Department and Agency strategy.

1.3 Objectives

The following are objectives of the FEMA Cyber Security Program:

• Perform gap analysis on current security infrastructure

• Ensure consistent application of information security standards across all agency information systems.

• Meet all regulatory and agency documented standards and guidance.

• Integrate these regulations and standards into a fully implementable security program.

• Ensure preparation for internal and external audits through management of all infrastructure artifacts required to pass audits.

• Ensure all new information technology (IT) projects meet or integrate security standards into their development.

• Develop a culture of security-mindful professionals across the community.

• Strive to be more flexible and responsive to new regulatory directives.

• Serve as the central authority for all Cyber Security-related activities across the agency.

• Ensure information system survivability and integrity.

• Optimize processes to meet Cyber Security-related goals and strategies

1.4 Applicable Documents

• National Institute of Standards and Technology (NIST), Special Publication (SP) 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems— A Security Life Cycle Approach, February 2010

• NIST SP 800-39, Managing Information Security Risk—Organization, Mission, and Information System View, March 2011

• NIST SP 500-53, Security and Privacy Controls for Federal Information Systems and Organizations

• NIST SP 500-53, Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans

• NIST SP 800-65, Integrating Cyber Security into the Capital Planning and Investment Control Process, dated January 2005

• 4300A Sensitive Systems Policy -- Version 11.0 http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Policy.pdf

• 4300A Sensitive Systems Policy Handbook -- Version 9.1 o Attachment B - Waivers Request Form -- Version 11 o Attachment C - ISSO Letter -- Version 11 o Attachment D - Type Accreditation -- Version 11 o Attachment E - FISMA Reporting -- Version11 o Attachment F - Incident Response -- Version 9.1 o Attachment G - Rules of Behavior -- Version 11 o Attachment H - POAM Process Guide -- UNDER REVISIONS -- Version 9.1 o Attachment I - Workstation Logon o Attachment K - IT Contingency Plan Template -- Version 11 o Attachment L - Password Management o Attachment M - 800-53 Controls -- Version11 o Attachment N - Interconnection Security Agreements -- Version 11 o Attachment O - Vulnerability Management -- Version 9.1 o Attachment P - Document Change Requests -- Version 11 o Attachment Q1 - Wireless Systems --Version 11 o Attachment Q2 - Mobile Devices -- Version 11 o Attachment Q3 - Tactical Systems o Attachment Q4 - RFID Systems -- Version 11 o Attachment R - Compliance Framework Guide -- Version 9.1 o Attachment S - Compliance Framework for Privacy Systems -- UNDER REVISIONS

-- Version 9.1 o Attachment S1 - Managing CREs containing SPII -- UNDER REVISIONS -- Version

9.1 o Attachment T - Acronyms o Attachment X - Social Media -- UNDER REVISIONS

• 4300B National Security System Policy Cover Page - Version 9.0

• 4300B National Security Systems Table of Contents - Version 9.0

• 4300B.100: Safeguarding and Risk Management for NSS

• 4300B.101 Risk Management for NSS

• 4300B.102 National Security System Security Control Guidance

• 4300B.103 Template Guidance o 4300B.103-1 Template for System Security Plans o 4300B.103-2 Template for Risk Assessment Reports o 4300B.103-3 Template for Security Assessment Reports o 4300B.103-4 Template for Plans of Action and Milestones

• 4300B.106 DHS NSS General and Privilege User Account Request Minimum Requirements

• 4300B.107 Decommissioning Strategy Minimum Requirements

• 4300B.108-1 National Security System References

• 4300B.108-2 National Security System Policy Change Request

• 4300B.200 Communication Security (COMSEC) - Version 2.0

• DHS Ongoing Authorization Methodology http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Handbook.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20B%5d%20Waiver%20Request%20Form.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20C%5d%20ISSO%20Letter.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20D%5d%20%20Type%20Accreditation.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20E%5d%20FISMA%20Reporting.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20F%5dIncident%20Response.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20G%5d%20%20Rules%20of%20Behavior.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20H%5dPOAM%20Guide.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20I%5dWorkstation%20Logon.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20K%5d%20%20IT%20Contingency%20Plan%20Template.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20L%5dPassword%20Management.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20M%5d%20Tailoring%20NIST%20800-53%20Security%20Ctrls.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20N%5d%20Interconnection%20Security%20Agreements.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20O%5dVulnerability%20Management.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20P%5d%20Document%20Change%20Requests.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q1%5d%20Sensitive%20Wireless%20Systems.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q2%5d%20Mobile%20Devices-CLEAN%20DRAFT.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q3%5dTactical%20Systems.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q4%5d%20Sensitive%20RFID%20Systems.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20R%5dCompli%20Fmwk%20CFO-designated%20Systems.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20S%5dCompliance%20Framework%20for%20Privacy%20Systems.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20S1%5dManaging%20CREs%20Containing%20SPII.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20T%5dAcronyms.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.000%20National%20Security%20Systems%20Policy%20Coverpage.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.000_TOC_4300B_05102013.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.100%20-%20Safeguarding%20and%20Risk%20Mgmt%20for%20NSS.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.100%20-%20Safeguarding%20and%20Risk%20Mgmt%20for%20NSS.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.101%20-%20Risk%20Management%20Framework.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.101%20-%20Risk%20Management%20Framework.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.102%20-%20NSS%20Security%20Control%20Guidance%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.102%20-%20NSS%20Security%20Control%20Guidance%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-1%20-%20System%20Security%20Plans%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-1%20-%20System%20Security%20Plans%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103.2%20-%20Risk%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103.2%20-%20Risk%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-3%20-%20Security%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-3%20-%20Security%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-4%20-%20Plans%20of%20Action%20and%20Milestones.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-4%20-%20Plans%20of%20Action%20and%20Milestones.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.107%20-%20Decommissioning%20Strategy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.107%20-%20Decommissioning%20Strategy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.108-1%20-%20NSS%20References.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.108.2%20-%20NSS%20Policy%20Change%20Request.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.200%20COMSEC.pdf

• DHS CISO NIST SP 800-53 Security Controls tri-fold

• DHS FISMA System Inventory Methodology

• DHS Information Security Performance Plan

• DHS Security Authorization Process Guide

• DHS Document Review Methodology

• Document Review Checklists

• Security Authorization Document Templates

• FIPS-199 Workbook and Instructions

• Privacy Threshold Analysis (PTA) Template

2.0 SPECIFIC TASKS

2.1 Task 1 - Project Management

2.1.1 Background

A project is a temporary group activity designed to produce a unique product, service or result.

A tasks and activities executed within the OCS are treated as projects. Contractor shall provide project management services for OCS tasks and activities. Project Management services shall adhere to the PMI Project Management framework for project planning, scheduling, communications, reporting, and contractual activity and to ensure that any technical issues are addressed quickly and professionally.

2.1.2 Clearance Requirement

All personnel supporting this task must have a SECRET clearance and adhere to guidance outline within Section 8.0 of this document.

2.1.3 Mission/Objectives/Goals

The Offeror’s Project Manager shall be responsible for the Project Planning and Project Management aspects of this task. This task continues for the entire duration of the project.

This task includes the regularly scheduled meetings and specified documentation; i.e., Weekly Status Meeting, Weekly Status Reports, Weekly Work, Plan Review, Schedule Review, and Oversight/Stakeholder Reporting.

The Offeror shall develop a Program Management Plan (PMP) for the successful execution of the tasks within this SOW. The PMP shall include, as a minimum:

• Statement of Objectives (SOO)

• Chart of organizational relationships, authority, and responsibilities

• Plan of Actions and Milestones (POA&M)

• Time-phased budget for cost control

• Project Risk Identification

• A requirements document

• A continuity of business plan detailing certification processes and practices to aid in the event of a change of contractors

Work products such as Weekly Activity Reports, Monthly Activity Reports, Program Status Reports, and meetings shall be included in the PMP.

The Offeror shall develop a Project Plan to manage, schedule, and track progress using Microsoft (MS) Project. The current progress information shall be provided to the Government through contractor management meetings, monthly activity reports, and MS Project files.

• Provide leadership, management, and administrative support for contractor work in support of Cyber Operations. Specific activities include but are not limited to the following:

• Provide overall management and oversight of contract staff and activities to ensure all work comply with applicable Department and OCIO policies and regulations; ensure contractor performance is timely and meets OCIO/CISO program goals and performance standards

• Provide overall technical leadership and oversight; recommend and oversee the implementation of proactive and leading edge technical and technological approaches and solutions to address emerging cyber security trends; report on an annual basis

• Provide administrative support for contract work activities to include support Cyber Operations; prepare memorandums and correspondence; perform filing, passing of clearances, meeting and conference coordination, and other office administration duties

• Provide and finalize the Program Management Plan within 20 business days of contract start date.

• Provide and finalize individual Task Management Plan that addresses at a minimum, performance schedule, milestones, deliverables, and approaches to problem resolution and communication and coordination with Government personnel within 20 business days of contract start

• Provide and finalize GFE Inventory Management Procedures within 20 business days of contract start

• Monitor and track program and task performance to ensure on time service delivery within established cost estimates

• Identify, recommend, and implement (upon Government approval) cost-saving measures

• Provide monthly Task Status Report for each task (to the designated Government Technical Monitor) by the 15th of each month, presenting:

o Activities and milestones completed and deliverables submitted for each task for the past month o Indication of potential schedule variance, mitigation strategies, and actions taken o Issues encountered and resolution applied o Issues unresolved and current status and actions o Milestones and activities planned for the next reporting period

• Provide monthly Program Status Report (to the Contracting Officer’s Representative) by the 15th of each month, incorporating the Task Status Reports and the following for the overall program:

o Total cost incurred in the past month and fiscal year-to-date o Indication of potential cost and/or schedule variance, mitigation strategies, and actions taken o Funding and expenditure status o Staffing status to include current staffing level (%); positions open/unfilled and number of days open/unfilled o Cost saving measures implementation status including activities and milestones completed and planned

• Conduct Program and individual Task Status Review monthly, as requested by the

Program Manager and/or COR, to provide opportunity for report clarification and issue resolution

• Prepare and conduct quarterly Program Performance Reviews (IAW Quality Assurance Surveillance Plan) to include identification of potential cost saving measures in each task area and related implementation plans and status

• Support acquisition of materials and services incidental to contractor work activities

The Offeror shall submit a written Monthly Activity and Program Status Reports, to include but not limited to:

• A summary of accomplishments for the month which includes ,

• Updated of the SOW Plan of Action and Milestones (POA&M) schedule (originally delivered as part of the PMP) including milestones achieved and schedule changes

• Funding expended and funding remaining

• A copy of deliverables submitted to the government for acceptance,

• Program risks identified and mitigation action taken and planned

• A narrative of management or technical problems,

• Suggestions and Recommendations, and

• A projected schedule for next month’s activities

The Offeror shall develop and submit the following management controls reports:

• Contract Management Meetings,

• Use of Automated Tools

• Quality Control (QC) and Quality Assurance (QA) Procedures

The Offeror shall provide consulting services for this task to the government.

2.1.3.1 Regular Contractor Management Meetings

The Offeror and FEMA shall hold regularly scheduled monthly Contractor Management Meetings. The meeting shall provide the government and the Offeror an opportunity to discuss current tasking, provide additional guidance to the technical task management of the contract, and give the Offeror an opportunity to ask questions pertinent to the successful completion of the task.

2.1.3.2 Quality Control and Quality Assurance Procedures

Quality of data is paramount importance to the FEMA. The Offeror plays a critical role in establishing and maintaining the quality of the program. The Offeror shall perform the following:

• Data Collection Quality Control (QC) – The Offeror shall develop and implement a written QC program for data collection to ensure compliance with DHS and FEMA processes and procedures.

• Data Quality Assurance (QA) – The Offeror shall support and participate in the DHS QA review program as defined by the requirements of Contractors QA Procedures. The Offeror shall provide propose corrective actions to the COR to address any minor deficiencies identified in the review within five working days of receiving the QA report.

If the Offeror receives an unacceptable QA rating, FEMA may suspend the Offeror’s activities, by written notice from the Contracting Officer (CO) until acceptable adjustments have been implemented and an acceptable QA is earned by the Offeror.

The Offeror shall report all activities during travel, in a format specified by the Contracting Officer’s Representative (COR).

2.2 Task 2 - Senior Technical Writer Support

The Technical Writer will be tasks by the CISO or designee to review documentation as required for submittal to internal, external customers. Ensure documentation meets FEMA Correspondence Policy, and Branding Standards if required. Ensure documents are reviewed in a timeline that is acceptable to Management including weekly status as a minimum. Maintain and update as required all Cyber Security documentation as directed by COR, or designee.

2.2.1 Background

2.2.2 Clearance Requirement

All personnel supporting this task must have a TOP SECRET clearance and adhere to guidance outline within Section 8.0 of this document.

2.2.3 Mission/Objectives/Goals

2.3 Task 3 - Security Engineering Support

2.3.1 Background

Cyber Security shall assist OCS with security architecture planning by ensuring its strategic goals and development of IT infrastructure supports the mission as well as its security objectives.

Cyber Security shall provide detailed, risk-based security reviews of products in support of requests for additions to the DHS approved products inventory. The documentation shall be sufficient to support the FEMA Enterprise Architecture Team in creating a Technical Insertion Package (TIP) as required by DHS. Support shall include, but not limited to:

• Ensuring Capital Planning and Investment Control (CPIC) processes with incorporated security controls described in IT investments are mapped to the security architecture;

communication with customer advocates to ensure Mission Need Statements are in compliance with IT Investment requirements;

• Attending all Engineering Review Boards; provide technical expertise, review of documentation, and providing recommendations to assist the FEMA CISO in approving configuration changes to systems being present at the Weekly Technical Review Changes (TRC) meeting;

• Developing a methodology for selecting security solutions; submit to the FEMA CISO for approval in compliance with approved DHS/FEMA Technical Requirements Matrix (TRM) and Technical Insertion Package (TIP);

• Identifying/assessing security controls and technologies that will enforce FEMA’s security policies as mandated during security reviews and product evaluations;

• Documenting the security architecture to provide recommendations of improvements to the FEMA CISO for review and approval.

2.3.1.1 Information Assurance

The Offeror shall ensure that all system or application deliverables meet the requirements of DHS and FEMA policy. Furthermore, the Offeror shall ensure that personnel performing Cyber Security activities obtain, and remain current with, required technical and/or management certifications.

2.3.1.2 System Cyber Security

For those solutions that will not inherit existing network security controls, and thus integrate an entirely new application system consisting of a combination of hardware, firmware and software, system security assurance is required at all layers of the Transmission Control Protocol/Internet Protocol (TCP/IP) Model. The Offeror shall ensure that all system deliverables comply with DHS and FEMA policy

The Offeror shall also support activities and meet the requirements of Public Key Infrastructure (PKI) and Public Key (PK) Enabling, in order to achieve standardized, PKI-supported capabilities for biometrics, digital signatures, encryption, identification, and authentication.

OCS requires security documentation and engineering/security testing/auditing/intrusion detection services to support and maintain Security Authorization of the program systems.

These services span a variety of Cyber Security activities necessary to complete a comprehensive evaluation of the technical and non-technical security features of the Financial information systems, Government-Off-The Shelf (GOTS) applications and network devices.

Support required includes development and maintenance of required security documentation, validation and evaluation of security requirements, vulnerabilities and residual risks, as well as effective continuous security auditing and monitoring for suspicious activity of the information systems. The Offeror shall provide the Cyber Security services listed below.

The Offeror shall accomplish thorough security testing for all systems servers, applications and network devices as part of the validation phase of NIST/DHS Security Authorization. Testing shall be accomplished IAW Government guidance, Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG), and established timelines to meet specific program needs. The Offeror shall stay abreast of the content of the security hardening guides and the updates to the security hardening guides.

In the case where a security hardening guides is not available, the Offeror shall research and develop Trusted Facility Manuals and Security Test and Evaluation (ST&E) Plans for all information systems servers, applications, and network devices.

The Offeror shall prepare Plan of Action and Milestones (POA&Ms) to identify security weaknesses for the all information systems.

The Offeror shall assist the Government with identifying security requirements and implementing security mechanisms. The Offeror shall stay abreast of current security vulnerabilities and potential implications to inform the Government of potential security threats to the systems and provide recommendations about how to avoid, minimize, correct, or recover from possible damage.

The Offeror shall provide engineering and technical expertise to include research or updates on new or upgraded operating systems, patches, hotfixes, applications, commercially available off-the-shelf (COTS) products, issue resolution, vulnerability evaluations, countermeasure implementation, ST&E, auditing/intrusion detection tools and all other security-relevant areas as required.

The Offeror must meet the following auditing requirements on all information systems.

• Ensure the security posture of the servers and network devices is maintained.

• Perform daily automated/continuous on-line monitoring of all information systems servers and network devices.

• Ensure audit trail creation capability is deployed.

• Ensure audit records are backed up not less than weekly onto a different system or media other than the system being audited.

• Ensure audit data is collected and retained to support technical analysis relating to misuse, penetration reconstruction, or other investigations. Upon request, provide this data to the Government or Contracting Officer Representative (COR)/Alternate COR.

• Ensure tools are available for the review of audit records and for report generation from audit records.

• Ensure the content of the audit trails is protected against unauthorized access, modification, or deletion.

The Offeror shall monitor local and remote all information systems for current security vulnerabilities and intrusion attempts on the all information systems system servers and network devices and immediately report findings to the Government or appropriate individual.

If the current auditing tools being used cannot detect the most current vulnerabilities/intrusion signatures, contractor shall research means to meet this requirement and provide a recommendation to the Government on tools to purchase or produce tools that would provide the required capabilities.

Some tools currently in use are ISS Server Sensor, Anomaly Detection Tool, HBSS, and Splunk.

There may be other tools coming on board later. The Offeror must be qualified in the use of monitoring tools and shall have knowledge to analyze the events from those tools to provide the Government with the true picture of risk or possible attack.

Upon identification of unusual, inappropriate or suspicious activity with potential Cyber Security implications, immediately alert Government or COR/Alternate COR.

Upon request, the Offeror shall generate a report of audit activity based on Government provided format and required content.

The Offeror shall monitor local and remote all information systems system firewalls for patterns of activity that are indicative of an attack or a probe prior to an attack (e.g., port scan). All IP addresses showing successful unauthorized activity shall be reported to the Government or COR/Alternate COR.

2.3.2 Clearance Requirement

All personnel supporting this task must have a TOP SECRET clearance and adhere to guidance outline within Section 8.0 of this document.

2.3.3 Mission/Operations/Goals

The Offeror shall provide the technical and administrative services necessary to support an accreditation decision.

2.4 Task 4 - Emerging Technology and Modernization Support

2.4.1 Background

2.4.2 Clearance Requirement

All personnel supporting this task must have a TOP SECRET clearance and adhere to guidance outline within Section 8.0 of this document.

2.4.3 Mission/Operations/Goals

Offeror shall investigate and document emerging technologies that could impact the way in which FEMA operates within the cyber domain. The Offeror shall provide recommendations to the COR for improvements to the overall FEMA Cyber Security mission.

There are both identified and anticipated but not specified technology enhancements that will become operational responsibilities during the course of this contract. The Offeror will provide support to OCS for the planning and implementation of these efforts. The Offeror will provide operational support on behalf of OCS these technology enhancements have been implemented.

The Offeror shall investigate and document emerging technologies that could impact the way in which the Army operates within the cyber domain. The Offeror shall provide recommendations to the COR for improvements to the overall OCS Cyber mission. The Offeror shall conduct this effort in accordance with C.4.

2.4.4 Tools Infrastructure Operational Support

Perform technical and operational support for security tools, products, solutions, and the supporting infrastructure to include the IT equipment and tools for use in conducting security assessments. Specific activities include but are not limited to the following:

• Provide 24x7x365 on-call, 8x5 weekdays on-site, maintenance support for all cyber security tools

• Ensure system backups are completed successfully and tested for quality

• Participate in testing and evaluation of new tools, technology and solutions

• Monitor availability of all security tools

• Track and report monthly on system performance statistics (i.e., storage, memory, and

CPU utilization)

• Maintain a minimum 95% availability of all tools; report on the availability and status of security tools

• Support OMB and FISMA reporting; respond to other requests for information including information on post-specific activities

• Provide monthly project status report as part of the Task Status Report by the 15th of each month

• Report on quality performance measures quarterly as part of the overall Program performance review

2.4.5 Procurement of Hardware, Software, and Services

<<INSERT ORDERING REQUIREMENT HERE>>

3.0 DELIVERABLES

This section list deliverables identified within Section 2.

The Offer shall deliverables electronically using Microsoft Office suite of tools (for example, MS WORD, MS EXCEL, MS POWERPOINT, MS PROJECT, or MS ACCESS format), unless otherwise specified by the COR. Electronic submission shall be made via email, unless otherwise agreed to by the COR.

SOW

TASK # DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

2.1. TASK 1 - PROJECT MANAGEMENT

2.1 Task 1 – Project Management Plan Contractor-

Determined Format Standard Distribution

2.1 Task 1 – Weekly Activity Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Monthly Activity Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Program Status Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Project Schedules Contractor-

Determined Format

Standard Distribution

2.1 Task 1 - GFE Inventory Management Procedures Contractor-

Determined Format

Standard Distribution

2.1 Task 1 - Program Performance Reviews Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Task POA&M Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Management Controls Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Meeting Minutes Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Travel Reports Contractor-

Determined Format

Standard Distribution

Monthly Performance and Progress Report Standard Distribution NLT 10th of each reporting period.

Program management plan Standard Distribution NLT 15 calendar DACA and updates as requested by COR Quality Assurance Plan (QAP) Standard Distribution NLT 15 calendar DACA and updates as requested by COR Monthly Performance and Progress Report Standard Distribution NLT 10th of each reporting period.

TASK # DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

Program management plan Standard Distribution NLT 15 calendar DACA and updates as requested by COR

Quality Assurance Plan (QAP) Standard Distribution NLT 15 calendar DACA and updates as requested by COR

In-briefs and Out-briefs

2.2 Task 2 – ISSO Contractor Support

2.2 Security Authorization documentation 60 days prior

going operational or the expiration of an authorization decision

Risk Assessment Report All changes and releases

Contingency Test Report Annually Non-Disclosure Agreement Annually Signed statements are due, from each employee assigned, prior to performing ANY work on this task.

ISSO Resumes ISSO Acknowledgement of Responsibilities Security C&A Phase 1 package reviews Standard Distribution Deliverables are provided within agreed upon project plan timeframe

C&A package revisions including required revisions in IACS or C-TAF

Standard Distribution Deliverables are provided within agreed upon project plan timeframe

IACS or C-TAF Compliance descriptions in IACS or C-TAF Standard Distribution Deliverables are provided within agreed upon project plan timeframe

Security Metrics Recommendations Standard Distribution Final recommendation developed within 120 calendar DACA

TASK # DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

Security Communications Plan Standard Distribution Final Plan developed within 90 calendar DACA

Procedure TRAINING Program Standard Distribution Final Program Plan developed within 180 calendar DACA

Vulnerability Testing and Scanning Report, Server configuration change report

Standard Distribution Report delivered by 15th of month

Project plan for Security Program Assessment Standard Distribution Final Plan developed within 60 calendar days of optional task order award

Security Program Improvement plan implementation Standard Distribution Implementation Plan developed within approved project plan timelines

Assessment of FS Centralized Account Management process Standard Distribution Final Plan developed within 60 calendar days of optional task order award recommendations for account management improvement Standard Distribution Final recommendations due within 120 calendar days of optional task award

Formal evaluation of Technical Approval requests Standard Distribution Evaluation submitted within 20 calendar days after receipt of technical approval request

Process improvement recommendations Standard Distribution Final recommendations due within 180 calendar days of optional task award

Wireless security assessments Standard Distribution Final assessment due within 120 calendar days of optional task award

LAN security assessments Standard Distribution Final assessment due within 120 calendar days of optional task award

Weekly interim status reports Standard Distribution Report due COB Monday

TASK # DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

Self Help Documentation Standard Distribution Final documentation due within 60 days of request

In-briefs and Out-briefs

2.3 Task 3 – 24x7 Security Operations Center Services

Cyber Security Briefing (CSB) Classified Cyber Security Briefing (CCSB) Daily Status Update on Significant Cases SPOT Report Daily Shift/Incident Log

2.4 Task 4 –Technical Writer Support FEMA

Month Weekly interim status reports

2.5 Task 5 - Agent of the Certifying Authority/Risk Executor Support Services BIA Crosswalk Report Standard Distribution Report due August 31 ITCP and DRP analyses Standard Distribution Analysis due Mar 1 Tabletop COOP exercises Standard Distribution Exercises due Feb 1 Functional COOP exercises Standard Distribution Exercises due Mar 1 Tabletop COOP after action report Standard Distribution Final report due 30 days after exercise date

TASK # DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

Functional COOP after action report Standard Distribution Final report due 30 days after exercise date

2.6 Task 6- Security Engineering Support

Formal evaluation of Technical Approval requests Process improvement recommendations Weekly interim status reports In-briefs and Out-briefs

2.7 – Task 7 - Documentation Management, Policy, Guidance and Publication Support Gap Analysis on procedures against policies and procedures Standard Distribution Analysis provided by January

Procedure Effectiveness Measurement Standard Distribution Report provided by August 1 Annual Procedure currency Review Standard Distribution Reviews submitted within 11 months of government's last procedure approval date

Updated Policy recommendations Standard Distribution Policy review submitted by November 1

New regulation recommendations Standard Distribution

Recommendation within 60 days of issuance

TASK # DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

Risk Management Strategy and CON-op recommendation Standard Distribution Final Strategy developed with 60 days of task order award and ConOps developed within 60 days of approved strategy

Risk Management Framework Strategy and Implementation Plan

Standard Distribution Plan developed within 60 days of approved ConOps, annual update due by September 30

Security Communications Plan Continuous Monitoring Plan Standard Distribution Plan developed, reviewed and implemented within 180 days of task order award

Corrective Action Plan Recommendation Standard Distribution Recommendation developed by June 15

Application Security Categorizations Standard Distribution Categorizations and results developed within 90 days after task order award for every lot of 25 migrations

Application Migration Status Reports Standard Distribution NLT 10th of each reporting period.

2.8 Task 8 – Audit and Assurance Services

A-123 Test Plan Development Standard Distribution Plans, assessments, and reports developed, reviewed, completed and reported in IACS or C-TAF by May 1

TASK # DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

A-123 Test control assessment documentation and compliance data entry in IACS or C-TAF

Standard Distribution Plans, assessments, and reports developed, reviewed, completed and reported in IACS or C-TAF by May 1

Weekly interim status reports In-briefs and Out-briefs

2.9 Task 9 – Security Awareness, Training and Education Services Security Communications Plan Procedure TRAINING Program Weekly interim status reports In-briefs and Out-briefs

2.10 Task 10 – System/Application Vulnerability and Penetration Testing Services Information System Security Plan / Update Standard Distribution

Final Program Plan developed within 120 calendar DACA, Update due by July 30

Vulnerability Testing and Scanning Report, Server configuration change report

Wireless security assessments LAN security assessments

2.11 Task 11 – A&A Support (Security Independent Verification and Validation) Information System Security Plan / Update Standard Distribution

Final Program Plan developed within 120 calendar DACA, Update due by July 30

TASK # DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

Security Metrics Recommendations Security Program Improvement plan implementation Project plan for Security Program Assessment

2.12 Task 12 – A&A Support (Cyber Security Resiliency)

Business Impact Assessments Standard Distribution

Final BIAs and physical security assessments provided within 90 days of onsite review

Program of Work for BIAs Standard Distribution POW for BIAs provided due Nov 1

Physical Security Assessments Standard Distribution Final BIAs and physical security assessments provided within 90 days of onsite review

Information System Security Plan / Update Standard Distribution

Final Program Plan developed within 120 calendar DACA, Update due by July 30

Weekly interim status reports In-briefs and Out-briefs

2.13 Task 13 – Emergency Technology and Modernization Support

TASK # DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

2.14 Task 14 – Adhoc and Surge Requirements

Formal evaluation of Technical Approval requests Process improvement recommendations

4.0 PLACE OF PERFORMANCE

4.1 Project Management

Primary work site:

FEMA Head Quarters Site National Capital Region Washington, DC

Alternate work site:

1. Mount Weather Emergency Operations Center

2. Alternate Security Operations Center site

3. Department of Homeland Security Operations Center

4. FEMA/DHS contracted datacenters

5. Other Government owned or leased site(s)

4.2 Technical Writer Support

Primary work site:

FEMA Head Quarters Site

6. Mount Weather Emergency Operations Center

7. Alternate Security Operations Center site

8. Department of Homeland Security Operations Center

9. FEMA/DHS contracted datacenters

10. Other Government owned or leased site(s)

4.3 Emerging Cyber Technology

Primary work site:

FEMA Head Quarters Site

11. Mount Weather Emergency Operations Center

12. Alternate Security Operations Center site

13. Department of Homeland Security Operations Center

14. FEMA/DHS contracted datacenters

15. Other Government owned or leased site(s)

4.4 Security Engineering Support

Primary work site:

FEMA Head Quarters Site

16. Mount Weather Emergency Operations Center

17. Alternate Security Operations Center site

18. Department of Homeland Security Operations Center

19. FEMA/DHS contracted datacenters

20. Other Government owned or leased site(s)

4.5 Emerging Technology and Modernization Support

Region IX - Oakland Headquarters Locations:

1111 Broadway, Oakland, Ca 94607-4052 75 North Fair Oaks Ave, Pasadena, CA 91103 1301 Clay St. Oakland, CA 94607 3720 Dudley Blvd, McClellan Park, CA 95652

Region VII - Kansas City Headquarters Locations:

9221 Ward Parkway, Suite 300, Kansas City, Mo 64114-3372 850 SW Chipman Rd, Suite 500, Lees Summit, MO 64063 2312 E Bannister Rd, Kansas City, MO 64131

Region V - Chicago Headquarters Locations:

536 S. Clark Street, Chicago, Il 60605 635 New Indian Trail Rd, Aurora, IL 60506

Region VI - Denton Regional Center, MERS, NPSC Locations:

Federal Regional Center 800 N. Loop 288 Denton, Texas 76209-3698 1500 Main, Baton Rouge, LA 70802 1 Seine Ct, New Orleans, LA 70114

Region VIII Denver Headquarters, MERS Location:

Building 710, Box 25267 Denver, Colorado 80225-0267

Region I Boston Headquarters, Maynard MERS Locations:

99 High Street, 6th Floor Boston, Massachusetts 02110

65 Old MOCSboro Rd, Maynard, MA 01754

Region II New York Headquarters Locations:

26 Federal Plaza, New York, New York 10278-0002 118-35 Queens Blvd, Forest Hills, NY 11375 11A Clinton Square Rm 741, Albany, NY 11227 NJ SRO 307 Middletown- Lincroft Rd, Middletown, NJ 07748 290 Broadway 29th Floor, New York City, NY 10007 201 State Route 34 South, Colts Neck, NJ 07722 159 COCSos Chardon Ave., Hato Rey, P.R. 00198

Region III Philadelphia Headquarters Locations:

One Independence Mall, 615 Chestnut Street Philadelphia, Pennsylvania 19106-4404 2570 Interstate Dr, Harrisburg, PA 17110

Region IV Atlanta Headquarters, Thomasville MERS Location1: 3003 Chamblee-Tucker Road, Atlanta, Georgia 30341 Location2: 402 South Pinetree Blvd., Thomasville, GA. 31792 Location3: Anniston, AL

Region Frederick MERS Location: 4420 Buckeystown Pike, Frederick, MD 20704

FEMA Headquarters Location1: DC Metropolitan Area (DMV) Location2: Brooke Rd. Facility, Winchester, VA Location3: Mt Weather Emergency Assistance Center Location4: Allegany Ballistics Laboratory Rocket Center, West Virginia Location5: Carpathia Hosting Inc. 43480 Yukon Dr. #200, Ashburn, VA 20147 Location6: 16825 S. Seaton Avenue, Emmitsburg, MD 21727-8998 Location7: 6511 America Boulevard, Hyattsville, MD Location8: 430 Market St. Winchester, VA Location9: 19844 Blue Ridge Mountain Rd. Bluemont, VA Location10: 500 C St. SW Washington, DC 20472

MERS, NIPSC, Logistic Centers Location: Various US Locations http://en.wikipedia.org/wiki/Allegany_Ballistics_Laboratory http://www.google.com/url?sa=t&rct=j&q=&esrc=s&frm=1&source=web&cd=1&cad=rja&ved=0CCkQFjAA&url=http%3A%2F%2Fwww.carpathiahost.com%2F&ei=ZQQFU6r9LYbGkQe7zIH4CQ&usg=AFQjCNEGm0neZjs2VzzsWd2BeO0TaDVN_A&sig2=W17iemgg9akgTTHQyzSCjg&bvm=bv.61535280,d.eW0

5.0 CERTIFICATIONS

If you find a dead link or we are missing a certification…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .