Information_System_Security_Officer_Draft_SOW.pdf

PDF 660 KB Posted

Attached to
FEMA INFORMATION TECHNOLOGY INDUSTRY DAY Federal contract opportunity
Solicitation number
HSFE30-15-S-0001
Issued by
Federal Emergency Management Agency Mitigation Section

View the file

Other files for this federal contract opportunity

Other files attached to FEMA INFORMATION TECHNOLOGY INDUSTRY DAY, newest first.
File Type Posted
FBO15.pdf PDF
FBO13_(002).pdf PDF
FBO12.pdf PDF
FBO11.pdf PDF
FBO10.pdf PDF
FBO9.pdf PDF
FBO8a.pdf PDF
FBO7replacement_(003).pdf PDF
FBO7_2272017.pdf PDF
FBO6_12202016.pdf PDF
FBO5b_(003).pdf PDF
FBO3_8APR16.pdf PDF
PWS6c-Security_Operations_Center_Support_v5.pdf PDF
PWS6b-Assessment_and_Authorization_Support_v5.pdf PDF
PWS6d-Emerging_Technology_and_Modernization_Support_v5.pdf PDF
PWS6a-Information_System_Security_Officer_v5.pdf PDF
PWSAPPLICATIONENGINEERING.pdf PDF
PWSOperations_and_Maintenance.pdf PDF
FBO.pdf PDF
OCISecurity5.pdf PDF
ITOCIrevised5_(3).pdf PDF
General_or_No_Category.pdf PDF
IT_Security.pdf PDF
Application_Development.pdf PDF
Mission_Needs.pdf PDF
Program_Management_Oversight.pdf PDF
QAIVV.pdf PDF
Hardware.pdf PDF
IT_Industry_Day_Roster_-_December_05_2014.pdf PDF
FEMA_IT_Industry_Day_Final_141205.pdf PDF
FEMA_BPA_Draft__Version_12__4__2014_(3).pdf PDF
Emerging_Technology_and_Modernization_Support_Draft_SOW.pdf PDF
FEMA_BPA_Hardware_Software_Draft.pdf PDF
REQUIREMENTS _ESTIMATES _AND_SCOPE_(RES).pdf PDF
Assessment_and_Authorization_Support_Draft_SOW.pdf PDF
Security_Operations_Center_Support.pdf PDF
O__M_-_DRAFT_SOW_09102014.pdf PDF
PMO_Contract_SOO-Draft_(2).pdf PDF
Application_Development_Engineering_and_Sustainment_Draft_SOW.pdf PDF
FEMA_Information_Technology_Industry_Day_Agenda.pdf PDF
OCIO_Procurement_Diagram.pdf PDF
FlyerIndustryDay.pdf PDF
Phased_Contract_Award_Approach_Flyer.pdf PDF
Socioeconomic_Disadvantage_Concerns_Flyer.pdf PDF
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PROCUREMENT SENSITIVE

Information System Security Officer Support

Statement of Work

INTENTIONALLY LEFT BLANK

ii

Table of Contents

1.0 Introduction

1.1 Scope

1.2 Background/Current Contract Environment

1.3 Objectives

1.4 Applicable Documents

2.0 Specific Tasks

2.1 Task 1 - Project Management

2.1.1 Background

2.1.2 Clearance Requirement

2.1.3 Mission/Objectives/Goals

2.2 Task 2 - Information System Security Officer Contractor Support

2.2.1 Background

2.2.2 Clearance Requirement

2.2.3 Mission/Objectives/Goals

2.2.4 Contractor Experience Requirements – Key Personnel

2.3 Task 3 – Adhoc and Surge Requirements

2.3.1 Background

2.3.2 Clearance Requirement

2.3.3 Mission/Operations/Goals

3.0 Deliverables

4.0 Place of Performance

4.1 Project Management

4.2 Information System Security Officer

5.0 Certifications

6.0 Government Furnished Information

7.0 Government Furnished Equipment (GFE)

8.0 Security Requirements

8.1 Access to Classified and Sensitive but Unclassified (SBU) Information

8.2 Employment Eligibility

i

8.3 Continued Eligibility

8.4 Suitability Determination

8.5 Background Investigations

8.6 Security Management

8.6.1 Information Technology Security Clearance

8.6.2 Information Technology Security Training and Oversight

9.0 Section 508 Compliance

9.1 Section 508 Applicable EIT Accessibility Standards

9.2 Section 508 Applicable Exceptions

9.3 Section 508 Compliance Requirements

10.0 Other Considerations

10.1 Travel Requirements

10.2 Inspection and Acceptance

10.3 Operating Constraints

Appenix A. Performance Based Matrix ii iii

1.0 INTRODUCTION

FEMA’s Chief Information System Officer (CISO) and staff is responsible for developing a comprehensive management approach for ensuring compliance with the Federal legislation, regulation and guidelines, departmental policies and procedures as well as ensuring systems operate at an acceptable risk. The CISO is Division Chief for the Office of Cyber Security (OCS) and reports directly to the FEMA Chief Information Officer (CIO). OCS functions as FEMA’s principal office for cyber security management, oversight, and issue resolution. The oversees FEMA’s Cyber Security Program by managing and controlling all aspects of security vulnerabilities, including conducting incident investigation, diagnosis, resolution, recovery, and closure, as well as establishing and maintaining security education and training programs.

OCS will utilize this contract vehicle for Cyber Security staff augmentation, services, and support

• Project Management provides project management services for OCS tasks and activities

• Information System Security Officer (ISSO) Contractor Support provides fully -qualified cyber security professional to server as ISSOs or Alternate ISSOs for FEMA Enterprise Information Systems, FEMA Program Information Systems, and Region Information Systems.

• Adhoc and Surge Requirement provide responses to OCS adhoc cyber security requests.

The Offeror shall provide experienced certified security professionals to serve as ISSOs over various FEMA systems.

1.1 Scope

Provide the expertise, technical knowledge, staff support, and other related resources necessary to:

• Perform analysis to ensure security controls are consistently implemented.

• Integrate new technology with Cyber Security standards.

• Develop and execute plans for monitoring, assessing, and verifying security controls across all major information systems.

• Develop, evaluate, and exercise IT survivability and contingency plans.

1.2 Background/Current Contract Environment

OCS provides cyber support to FEMA’s emergency management and continuity mission by utilizing the Federal Cyber Security Framework, in order to

• Identify risks to systems, assets, data, and capabilities;

• Protect mission essential and critical services;

• Detect cybersecurity events;

• Respond to detected cybersecurity events; and

• Recover capabilities or services that were impaired due to a cybersecurity event.

OCS plans, coordinates, integrates, synchronizes, and conducts activities that lead day-to-day safeguarding and protection of FEMA information systems (directly and indirectly connected to the FEMA infrastructure). At a minimum, OCS supports information within the continental United States (CONUS) and outside the continental United States (OCONUS). These systems may reside at the FEMA Headquarter within the National Capital Region; the 10 Regional Offices; 8 Distribution Centers, and the various Disaster Emergency Communications facilities.

The Top Technology challenges are face by OCS are:

1. Resiliency – Resilient Architecture and Operations

2. Automated Risk Detection-monitoring Heuristic/Behavioral - Large scale/Real-time/Multi-domain

3. Automated Risk Mitigation

4. Usability – Transparent Security

5. Cloud - Store Sensitive Government Data Searchable and Usable on Public Clouds

6. Detection and Response Mechanisms for Insiders (Timely, Fine-grained)

7. Leverage Classified Knowledge/Signatures in a Host-based System

8. Mobility - Hardware RoT, SEAndroid, Secure boot, Secure Baseband

9. Security for Cloud User Environments – Thick/Thin Client, Virtualization

10. Engineering, Testing, and Operating Secure Composite Systems

11. Establishing and Maintaining Assurance in Heterogeneous, Mobile and Cloud

Environments

FEMA’s mission is to reduce the loss of life and property and protect communities nationwide from all hazards, including natural disasters, acts of terrorism, and other manmade disasters.

FEMA leads and supports the nation in a risk-based, comprehensive emergency management system of preparedness, response, recovery, assistance, and mitigation. In support of this mission, FEMA uses a wide variety of information systems and IT solutions and services. These systems, solutions, and services must be operated and maintained at the highest level of confidentiality, availability, and integrity.

OCS will provide oversight and management of the work and tasks orders under this Statement of Work. The mission of the FEMA OCIO is “to enhance and maintain IT infrastructure; develop and enhance key systems to support operating programs; increase efficiencies and cooperation across FEMA’s divisional and regional lines.” The vision and strategy of the OCIO is to modernize FEMA IT systems and services and to “deliver world-class secure IT guidance, products, and services to meet the needs of FEMA’s emergency managers and stakeholders nationwide.” The environment must be implemented with the flexibility required to support the evolving mission of FEMA and to support the surge requirements necessary to support emergency situations as they occur.

http://en.wiktionary.org/wiki/continental_United_States

Currently, FEMA’s IT environment is an amalgam of new and legacy technologies, architectures, platforms, and tools that includes a wide variety of PC-based, client-server, web-based and service-oriented components. The IT systems supporting FEMA’s mission has been implemented by using a variety of service providers under both mature and immature oversight and governance conditions. As stated above, the current goals are to continue the evolution and improvement of all IT services and support. The OCIO goal will be achieved by utilizing an approach and strategy that is consistent with both the Department and Agency strategy.

1.3 Objectives

The following are objectives of the FEMA Cyber Security Program:

• Perform gap analysis on current security infrastructure

• Ensure consistent application of information security standards across all agency information systems.

• Meet all regulatory and agency documented standards and guidance.

• Integrate these regulations and standards into a fully implementable security program.

• Ensure preparation for internal and external audits through management of all infrastructure artifacts required to pass audits.

• Ensure all new information technology (IT) projects meet or integrate security standards into their development.

• Develop a culture of security-mindful professionals across the community.

• Strive to be more flexible and responsive to new regulatory directives.

• Serve as the central authority for all Cyber Security-related activities across the agency.

• Ensure information system survivability and integrity.

• Optimize processes to meet Cyber Security-related goals and strategies

1.4 Applicable Documents

• National Institute of Standards and Technology (NIST), Special Publication (SP) 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems— A Security Life Cycle Approach, February 2010

• NIST SP 800-39, Managing Information Security Risk—Organization, Mission, and Information System View, March 2011

• NIST SP 500-53, Security and Privacy Controls for Federal Information Systems and Organizations

• NIST SP 500-53, Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans

• NIST SP 800-65, Integrating Cyber Security into the Capital Planning and Investment Control Process, dated January 2005

• 4300A Sensitive Systems Policy -- Version 11.0

• 4300A Sensitive Systems Policy Handbook -- Version 9.1 o Attachment B - Waivers Request Form -- Version 11 o Attachment C - ISSO Letter -- Version 11 o Attachment D - Type Accreditation -- Version 11 http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Policy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Handbook.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20B%5d%20Waiver%20Request%20Form.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20C%5d%20ISSO%20Letter.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20D%5d%20%20Type%20Accreditation.docx o Attachment E - FISMA Reporting -- Version11 o Attachment F - Incident Response -- Version 9.1 o Attachment G - Rules of Behavior -- Version 11 o Attachment H - POAM Process Guide -- UNDER REVISIONS -- Version 9.1 o Attachment I - Workstation Logon o Attachment K - IT Contingency Plan Template -- Version 11 o Attachment L - Password Management o Attachment M - 800-53 Controls -- Version11 o Attachment N - Interconnection Security Agreements -- Version 11 o Attachment O - Vulnerability Management -- Version 9.1 o Attachment P - Document Change Requests -- Version 11 o Attachment Q1 - Wireless Systems --Version 11 o Attachment Q2 - Mobile Devices -- Version 11 o Attachment Q3 - Tactical Systems o Attachment Q4 - RFID Systems -- Version 11 o Attachment R - Compliance Framework Guide -- Version 9.1 o Attachment S - Compliance Framework for Privacy Systems -- UNDER REVISIONS

-- Version 9.1 o Attachment S1 - Managing CREs containing SPII -- UNDER REVISIONS -- Version

9.1 o Attachment T - Acronyms o Attachment X - Social Media -- UNDER REVISIONS

• 4300B National Security System Policy Cover Page - Version 9.0

• 4300B National Security Systems Table of Contents - Version 9.0

• 4300B.100: Safeguarding and Risk Management for NSS

• 4300B.101 Risk Management for NSS

• 4300B.102 National Security System Security Control Guidance

• 4300B.103 Template Guidance o 4300B.103-1 Template for System Security Plans o 4300B.103-2 Template for Risk Assessment Reports o 4300B.103-3 Template for Security Assessment Reports o 4300B.103-4 Template for Plans of Action and Milestones

• 4300B.106 DHS NSS General and Privilege User Account Request Minimum Requirements

• 4300B.107 Decommissioning Strategy Minimum Requirements

• 4300B.108-1 National Security System References

• 4300B.108-2 National Security System Policy Change Request

• 4300B.200 Communication Security (COMSEC) - Version 2.0

• DHS Ongoing Authorization Methodology

• DHS CISO NIST SP 800-53 Security Controls tri-fold

• DHS FISMA System Inventory Methodology

• DHS Information Security Performance Plan http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20E%5d%20FISMA%20Reporting.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20F%5dIncident%20Response.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20G%5d%20%20Rules%20of%20Behavior.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20H%5dPOAM%20Guide.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20I%5dWorkstation%20Logon.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20K%5d%20%20IT%20Contingency%20Plan%20Template.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20L%5dPassword%20Management.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20M%5d%20Tailoring%20NIST%20800-53%20Security%20Ctrls.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20N%5d%20Interconnection%20Security%20Agreements.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20O%5dVulnerability%20Management.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20P%5d%20Document%20Change%20Requests.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q1%5d%20Sensitive%20Wireless%20Systems.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q2%5d%20Mobile%20Devices-CLEAN%20DRAFT.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q3%5dTactical%20Systems.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q4%5d%20Sensitive%20RFID%20Systems.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20R%5dCompli%20Fmwk%20CFO-designated%20Systems.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20S%5dCompliance%20Framework%20for%20Privacy%20Systems.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20S1%5dManaging%20CREs%20Containing%20SPII.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20T%5dAcronyms.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.000%20National%20Security%20Systems%20Policy%20Coverpage.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.000_TOC_4300B_05102013.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.100%20-%20Safeguarding%20and%20Risk%20Mgmt%20for%20NSS.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.100%20-%20Safeguarding%20and%20Risk%20Mgmt%20for%20NSS.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.101%20-%20Risk%20Management%20Framework.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.101%20-%20Risk%20Management%20Framework.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.102%20-%20NSS%20Security%20Control%20Guidance%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.102%20-%20NSS%20Security%20Control%20Guidance%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-1%20-%20System%20Security%20Plans%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-1%20-%20System%20Security%20Plans%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103.2%20-%20Risk%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103.2%20-%20Risk%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-3%20-%20Security%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-3%20-%20Security%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-4%20-%20Plans%20of%20Action%20and%20Milestones.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-4%20-%20Plans%20of%20Action%20and%20Milestones.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.107%20-%20Decommissioning%20Strategy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.107%20-%20Decommissioning%20Strategy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.108-1%20-%20NSS%20References.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.108.2%20-%20NSS%20Policy%20Change%20Request.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.200%20COMSEC.pdf

• DHS Security Authorization Process Guide

• DHS Document Review Methodology

• Document Review Checklists

• Security Authorization Document Templates

• FIPS-199 Workbook and Instructions

• Privacy Threshold Analysis (PTA) Template

2.0 SPECIFIC TASKS

2.1 Task 1 - Project Management

2.1.1 Background

A project is a temporary group activity designed to produce a unique product, service or result.

A tasks and activities executed within the OCS are treated as projects. Contractor shall provide project management services for OCS tasks and activities. Project Management services shall adhere to the PMI Project Management framework for project planning, scheduling, communications, reporting, and contractual activity and to ensure that any technical issues are addressed quickly and professionally.

2.1.2 Clearance Requirement

All personnel supporting this task must have a SECRET clearance and adhere to guidance outline within Section 8.0 of this document.

2.1.3 Mission/Objectives/Goals

The Offeror’s Project Manager shall be responsible for the Project Planning and Project Management aspects of this task. This task continues for the entire duration of the project.

This task includes the regularly scheduled meetings and specified documentation; i.e., Weekly Status Meeting, Weekly Status Reports, Weekly Work, Plan Review, Schedule Review, and Oversight/Stakeholder Reporting.

The Offeror shall develop a Program Management Plan (PMP) for the successful execution of the tasks within this SOW. The PMP shall include, as a minimum:

• Statement of Objectives (SOO)

• Chart of organizational relationships, authority, and responsibilities

• Plan of Actions and Milestones (POA&M)

• Time-phased budget for cost control

• Project Risk Identification

• A requirements document

• A continuity of business plan detailing certification processes and practices to aid in the event of a change of contractors

Work products such as Weekly Activity Reports, Monthly Activity Reports, Program Status Reports, and meetings shall be included in the PMP.

The Offeror shall develop a Project Plan to manage, schedule, and track progress using Microsoft (MS) Project. The current progress information shall be provided to the Government through contractor management meetings, monthly activity reports, and MS Project files.

• Provide leadership, management, and administrative support for contractor work in support of Cyber Operations. Specific activities include but are not limited to the following:

• Provide overall management and oversight of contract staff and activities to ensure all work comply with applicable Department and OCIO policies and regulations; ensure contractor performance is timely and meets OCIO/CISO program goals and performance standards

• Provide overall technical leadership and oversight; recommend and oversee the implementation of proactive and leading edge technical and technological approaches and solutions to address emerging cyber security trends; report on an annual basis

• Provide administrative support for contract work activities to include support Cyber Operations; prepare memorandums and correspondence; perform filing, passing of clearances, meeting and conference coordination, and other office administration duties

• Provide and finalize the Program Management Plan within 20 business days of contract start date.

• Provide and finalize individual Task Management Plan that addresses at a minimum, performance schedule, milestones, deliverables, and approaches to problem resolution and communication and coordination with Government personnel within 20 business days of contract start

• Provide and finalize GFE Inventory Management Procedures within 20 business days of contract start

• Monitor and track program and task performance to ensure on time service delivery within established cost estimates

• Identify, recommend, and implement (upon Government approval) cost-saving measures

• Provide monthly Task Status Report for each task (to the designated Government Technical Monitor) by the 15th of each month, presenting:

o Activities and milestones completed and deliverables submitted for each task for the past month o Indication of potential schedule variance, mitigation strategies, and actions taken o Issues encountered and resolution applied o Issues unresolved and current status and actions o Milestones and activities planned for the next reporting period

• Provide monthly Program Status Report (to the Contracting Officer’s Representative) by the 15th of each month, incorporating the Task Status Reports and the following for the overall program:

o Total cost incurred in the past month and fiscal year-to-date o Indication of potential cost and/or schedule variance, mitigation strategies, and actions taken o Funding and expenditure status o Staffing status to include current staffing level (%); positions open/unfilled and number of days open/unfilled o Cost saving measures implementation status including activities and milestones completed and planned

• Conduct Program and individual Task Status Review monthly, as requested by the

Program Manager and/or COR, to provide opportunity for report clarification and issue resolution

• Prepare and conduct quarterly Program Performance Reviews (IAW Quality Assurance Surveillance Plan) to include identification of potential cost saving measures in each task area and related implementation plans and status

• Support acquisition of materials and services incidental to contractor work activities

The Offeror shall submit a written Monthly Activity and Program Status Reports, to include but not limited to:

• A summary of accomplishments for the month which includes ,

• Updated of the SOW Plan of Action and Milestones (POA&M) schedule (originally delivered as part of the PMP) including milestones achieved and schedule changes

• Funding expended and funding remaining

• A copy of deliverables submitted to the government for acceptance,

• Program risks identified and mitigation action taken and planned

• A narrative of management or technical problems,

• Suggestions and Recommendations, and

• A projected schedule for next month’s activities

The Offeror shall develop and submit the following management controls reports:

• Contract Management Meetings,

• Use of Automated Tools

• Quality Control (QC) and Quality Assurance (QA) Procedures

The Offeror shall provide consulting services for this task to the government.

2.1.3.1 Regular Contractor Management Meetings

The Offeror and FEMA shall hold regularly scheduled monthly Contractor Management Meetings. The meeting shall provide the government and the Offeror an opportunity to discuss current tasking, provide additional guidance to the technical task management of the contract, and give the Offeror an opportunity to ask questions pertinent to the successful completion of the task.

2.1.3.2 Quality Control and Quality Assurance Procedures

Quality of data is paramount importance to the FEMA. The Offeror plays a critical role in establishing and maintaining the quality of the program. The Offeror shall perform the following:

• Data Collection Quality Control (QC) – The Offeror shall develop and implement a written QC program for data collection to ensure compliance with DHS and FEMA processes and procedures.

• Data Quality Assurance (QA) – The Offeror shall support and participate in the DHS QA review program as defined by the requirements of Contractors QA Procedures. The Offeror shall provide propose corrective actions to the COR to address any minor deficiencies identified in the review within five working days of receiving the QA report.

If the Offeror receives an unacceptable QA rating, FEMA may suspend the Offeror’s activities, by written notice from the Contracting Officer (CO) until acceptable adjustments have been implemented and an acceptable QA is earned by the Offeror.

The Offeror shall report all activities during travel, in a format specified by the Contracting Officer’s Representative (COR).

2.2 Task 2 - Information System Security Officer Contractor Support DHS policy requires the Information System Security Officer (ISSO) be appointment to every IT system. The Offeror shall provide qualified, proficient and certified security professional.

These personnel shall be designated as key personnel. Key personnel shall be approved by the CISO and COR, to serve as ISSO in accordance with DHS policy. The ISSO shall serve as the point of contact (POC) for all security matter related to their assigned system. Once appointed by the CISO, the ISSO shall study and be familiar with the following documentation:

• DHS System Policies and Handbooks (DHS Directive 4300A or 4300B)

• DHS Security Authorization Guide

• DHS ISSO Guide

• DHS Information Security Performance Plan

• FEMA Directive 140-1 as well as other relevant security policy

The Offeror shall provide the CISO with the designees resume and shall meet the experience requirements within Section Error! Reference source not found.. In addition, the Offeror shall provide DHS ISSO/AISSO Roles and Acknowledgement as well as a Non-Disclosure Agreement for each candidate approved to start.

2.2.1 Background

ISSOs are official appointed by the CISO and designated by the System Owner to ensure FEMA’s information system are operating and maintained FEMA’s information system or information systems at the appropriate operational. ISSOs assists in identifying, implementing, and assessing the common security controls; and actively supporting the development and maintenance of the security plan, to include coordinating system changes with the information system owner and assessing the security impact of those changes. ISSOs serve as Technical Advisor to the CISO and System Owner on all areas of cyber security and as such, responsible for:

• Maintaining ongoing knowledge: (a) of Federal legislation, regulation, policies, and practices related to cyber security; (b) methodologies and best practices that are commonly used in the cyber security industry; (c) the status of Federal Cyber Security initiatives; (d) automation architectures used at FEMA; (e) COTS software packages;

custom developed software applications; and network and telecommunications products and technologies; and, (f) the threats to and vulnerabilities.

• Recommending courses of action and policies to senior management that allow FEMA to securely meet the organizational goals.

• Managing the monitoring and recording the performance of cyber security initiatives for FEMA and regularly reporting its status to the AO, DAO, CISO, ISSM and SO. The ISSO prepared to report and memorandum of records regarding the cyber security status of their assigned system for FEMA leadership review and signature.

2.2.2 Clearance Requirement

All personnel supporting this task may be required to have SECRET, TOP SECRET, or TOP SECRET/SCI clearance and adhere to guidance outline within Section 8.0 of this document.

2.2.3 Mission/Objectives/Goals

OMB Circular A-130 requires all Information system or information systems to be authorized in accordance with the National Institute Standards and Technology (NIST) guidelines and standards. DHS security authorization process for certifying and accrediting an information systems complies with the guidelines and standards published by NIST. ISSOs shall devise a plan to certify and accredit their assigned Information system or information systems. ISSOs shall ensure their assigned Information system or information systems receives a favorable authorization decision by ensuring all required security authorization artifacts are developed and maintained in accordance with DHS and FEMA standards. ISSOs shall adhere to guidelines and standards defined within the current year Security Authorization Guide and the DHS Information Security Performance Plan.

Specific objectives associated with the artifacts of each security authorization package are delineated below:

• Federal Information Processing Standards Publications 199

• Risk Assessment

• Privacy Threshold Assessment

• Privacy Impact Assessment (if required)

• Security Plan

• Contingency Plan

• Security Control Testing Support

• Plan of Action and Milestone (POA&M)

• Standard Operation Procedures

• System Specific Policies

The Offeror shall assist the CISO and System Owners with maintaining the security posture of their assigned information system or information systems. The Offeror shall provide cyber security professions that meet or exceeds the security labor categories. The Offer shall provide personnel with extensive knowledge and hands on experience the following areas:

• Security Fundamentals o Defense in Depth o Risk Management

• Data classification and labeling

• Regulations, Legislation and Guidance

• Firewalls and Intrusion Protection/Detection Systems

• Network (VLANS, VPNS, wireless, etc.)

• Communication protocols and services

• Encryption

• Risk and Threat Management

• Vulnerability Assessment and Management

• Incident Response

• Audit Log Review

• Operating Systems (Window, LINUX, etc.)

• Database (SQL, Oracle, etc.)

• Content Management

• Hardening of servers and mobile devices (laptops, iPhones, Android devices, etc.)

• Hardening of network appliances and devices

The Offeror shall support all activities that ensure the level of security documented with the security authorization is maintained. Activities can include, but not limited to, the following:

• Monitoring the status of POA&Ms to ensure weaknesses are resolved

• Conducting an annual assessment in accordance with guidance in the DHS Information

Security Performance Plan

• Reviewing and updating security authorization documents as needed, but at least annually

• Conducting Contingency Plan tests at least annually and updating the plan

• Conducting periodic scans of the system to ensure the configuration remains compliant with DHS guidance

• Ensuring CM processes are followed to ensure that any changes do not introduce new security risks

• Providing weekly incident response reports to the FEMA Security Operations Center

(SOC)

The Offeror must be able to provide support throughout the United States (CONUS and OCONUS). In addition, the Offeror must be able to support FEMA’s disaster operations during a disaster declaration or an emergency.

The Offeror shall provide consulting services for this task to the government.

2.2.4 Contractor Experience Requirements – Key Personnel

Working with the FEMA CISO, the Offeror shall provide experienced certified cyber security professionals (CISSP, CAP, CISA, CISM, Security+) to serve as Information System Security Officer at FEMA. In addition, the personnel shall have a technology certification along with cyber security certification. A limited list of the information technology certifications acceptable is listed within Section 5.0.

The security professional resumes shall submit to the government to perform this work will be defined as key personnel. The Offeror agrees that such personnel shall not be removed, diverted, or replaced from work without prior written approval of the COR, CISO or designee and the Contracting Officer.

Any personnel the Offeror offers as substitutes shall have the ability and qualifications equal to or better than the original key personnel that are being replaced. Upon government acceptance of the substitution, this individual shall also be defined as key personnel. Requests to substitute personnel shall be approved by the COR, CISO or OCS designee and the Contracting Officer. All requests for approval of substitutions in personnel shall be submitted to the Contracting Officer within 30 calendar days prior to making any change in key personnel.

The request shall be written and provide a detailed explanation of the circumstances necessitating the proposed substitution. The Offeror shall submit a complete resume for the proposed substitute, any changes to the rate specified in the order (as applicable), and any other information requested by the Contracting Officer needed to approve or disapprove the proposed substitution. The COR, CISO or OCS designee and Contracting Officer will evaluate such requests and promptly notify the Offeror of approval or disapproval thereof in writing.

Prior to starting, all personnel must sign a FEMA Non-Disclosure Agreement.

2.3 Task 3 – Adhoc and Surge Requirements

2.3.1 Background

This is applicable to all of the Task Areas. Ad hoc and surge requirements, within the scope of the requirement, will most certainly arise during the life of this contract. These situations will require the Offeror to respond with very little notice. Since response to these emergencies will not allow time to identify additional personnel, the Offeror’s personnel performing on current tasks will be diverted to these emergency requirements. If these requirements become prolonged, the Offeror may be requested to backfill personnel for various tasks to replace the personnel that have been diverted. Any changes to the FFP tasks will be dealt with through the Changes Clause.

2.3.2 Clearance Requirement

All personnel supporting this task must have a SECRET clearance and adhere to guidance outline within Section 8.0 of this document.

2.3.3 Mission/Operations/Goals

The Offeror shall provide consulting services for this task to the government.

3.0 DELIVERABLES

This section list deliverables identified within Section 2.

The Offer shall deliverables electronically using Microsoft Office suite of tools (for example, MS WORD, MS EXCEL, MS POWERPOINT, MS PROJECT, or MS ACCESS format), unless otherwise specified by the COR. Electronic submission shall be made via email, unless otherwise agreed to by the COR.

SOW TASK

# DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

2.1. TASK 1 - PROJECT MANAGEMENT

2.1 Task 1 – Project Management Plan Contractor-

Determined Format Standard Distribution

2.1 Task 1 – Weekly Activity Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Monthly Activity Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Program Status Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Project Schedules Contractor-

Determined Format

Standard Distribution

2.1 Task 1 - GFE Inventory Management Procedures Contractor-

Determined Format

Standard Distribution

2.1 Task 1 - Program Performance Reviews Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Task POA&M Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Management Controls Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Meeting Minutes Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Travel Reports Contractor-

Determined Format

Standard Distribution

Monthly Performance and Progress Report Contractor- Determined Format

Standard Distribution NLT 10th of each reporting period.

Program management plan Contractor- Determined Format

Standard Distribution NLT 15 calendar DACA and updates as requested by COR

Quality Assurance Plan (QAP) Contractor- Determined Format

Standard Distribution NLT 15 calendar DACA and updates as requested by COR

Monthly Performance and Progress Report Contractor- Determined Format

Standard Distribution NLT 10th of each reporting period.

# DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

Program management plan Contractor- Determined Format

Standard Distribution NLT 15 calendar DACA and updates as requested by COR

Quality Assurance Plan (QAP) Contractor- Determined Format

Standard Distribution NLT 15 calendar DACA and updates as requested by COR

In-briefs and Out-briefs Contractor- Determined Format

Standard Distribution

2.2 Task 2 – ISSO Contractor Support

2.2 Security Authorization documentation To be identified at

award Standard Distribution 60 days prior going operational or the expiration of an authorization decision

Risk Assessment Report To be identified at award

Standard Distribution All changes and releases

Contingency Test Report To be identified at award

Standard Distribution Annually

Non-Disclosure Agreement To be identified at award

Standard Distribution Annually Signed statements are due, from each employee assigned, prior to performing ANY work on this task.

ISSO Resumes To be identified at award

Standard Distribution

ISSO Acknowledgement of Responsibilities To be identified at award

Standard Distribution

Security C&A Phase 1 package reviews To be identified at award

Standard Distribution Deliverables are provided within agreed upon project plan timeframe

C&A package revisions including required revisions in IACS or C-TAF

To be identified at award

Standard Distribution Deliverables are provided within agreed upon project plan timeframe

IACS or C-TAF Compliance descriptions in IACS or C-TAF To be identified at award

Standard Distribution Deliverables are provided within agreed upon project plan timeframe

# DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

Security Metrics Recommendations To be identified at award

Standard Distribution Final recommendation developed within 120 calendar DACA

Security Communications Plan To be identified at award

Standard Distribution Final Plan developed within 90 calendar DACA

Procedure TRAINING Program To be identified at award

Standard Distribution Final Program Plan developed within 180 calendar DACA

Vulnerability Testing and Scanning Report, Server configuration change report

To be identified at award

Standard Distribution Report delivered by 15th of month

Project plan for Security Program Assessment To be identified at award

Standard Distribution Final Plan developed within 60 calendar days of optional task order award

Security Program Improvement plan implementation To be identified at award

Standard Distribution Implementation Plan developed within approved project plan timelines

Assessment of FS Centralized Account Management process To be identified at award

Standard Distribution Final Plan developed within 60 calendar days of optional task order award recommendations for account management improvement To be identified at award

Standard Distribution Final recommendations due within 120 calendar days of optional task award

Formal evaluation of Technical Approval requests To be identified at award

Standard Distribution Evaluation submitted within 20 calendar days after receipt of technical approval request

Process improvement recommendations To be identified at award

Standard Distribution Final recommendations due within 180 calendar days of optional task award

Wireless security assessments To be identified at award

Standard Distribution Final assessment due within 120 calendar days of optional task award

# DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

LAN security assessments To be identified at award

Standard Distribution Final assessment due within 120 calendar days of optional task award

Weekly interim status reports To be identified at award

Standard Distribution Report due COB Monday

Self Help Documentation To be identified at award

Standard Distribution Final documentation due within 60 days of request

In-briefs and Out-briefs To be identified at award

Standard Distribution

2.14 Task 14 – Adhoc and Surge Requirements

Formal evaluation of Technical Approval requests To be identified at award Standard Distribution

Process improvement recommendations To be identified at award

Standard Distribution

In-briefs and Out-briefs To be identified at award

Standard Distribution

4.0 PLACE OF PERFORMANCE

4.1 Project Management

Primary work site:

FEMA Head Quarters Site National Capital Region Washington, DC

Alternate work site:

1. Mount Weather Emergency Operations Center

2. Alternate Security Operations Center site

3. Department of Homeland Security Operations Center

4. FEMA/DHS contracted datacenters

5. Other Government owned or leased site(s)

4.2 Information System Security Officer

The FEMA Stakeholder Office Location will determine the work site. The site locations are and not limited to:

Region IX - Oakland Headquarters Locations:

1111 Broadway, Oakland, Ca 94607-4052 75 North Fair Oaks Ave, Pasadena, CA 91103 1301 Clay St. Oakland, CA 94607 3720 Dudley Blvd, McClellan Park, CA 95652

Region VII - Kansas City Headquarters Locations:

9221 Ward Parkway, Suite 300, Kansas City, Mo 64114-3372 850 SW Chipman Rd, Suite 500, Lees Summit, MO 64063 2312 E Bannister Rd, Kansas City, MO 64131

Region V - Chicago Headquarters Locations:

536 S. Clark Street, Chicago, Il 60605 635 New Indian Trail Rd, Aurora, IL 60506

Region VI - Denton Regional Center, MERS, NPSC Locations:

Federal Regional Center 800 N. Loop 288 Denton, Texas 76209-3698 1500 Main, Baton Rouge, LA 70802 1 Seine Ct, New Orleans, LA 70114

Region VIII Denver Headquarters, MERS Location:

Building 710, Box 25267 Denver, Colorado 80225-0267

Region I Boston Headquarters, Maynard MERS Locations:

99 High Street, 6th Floor Boston, Massachusetts 02110 65 Old MOCSboro Rd, Maynard, MA 01754

Region II New York Headquarters Locations:

26 Federal Plaza, New York, New York 10278-0002 118-35 Queens Blvd, Forest Hills, NY 11375 11A Clinton Square Rm 741, Albany, NY 11227 NJ SRO 307 Middletown- Lincroft Rd, Middletown, NJ 07748 290 Broadway 29th Floor, New York City, NY 10007 201 State Route 34 South, Colts Neck, NJ 07722 159 COCSos Chardon Ave., Hato Rey, P.R. 00198

Region III Philadelphia Headquarters Locations:

One Independence Mall, 615 Chestnut Street Philadelphia, Pennsylvania 19106-4404 2570 Interstate Dr, Harrisburg, PA 17110

Region IV Atlanta Headquarters, Thomasville MERS Location1: 3003 Chamblee-Tucker Road, Atlanta, Georgia 30341 Location2: 402 South Pinetree Blvd., Thomasville, GA. 31792 Location3: Anniston, AL

Region Frederick MERS Location: 4420 Buckeystown Pike, Frederick, MD 20704

FEMA Headquarters Location1: DC Metropolitan Area (DMV) Location2: Brooke Rd. Facility, Winchester, VA Location3: Mt Weather Emergency Assistance Center Location4: Allegany Ballistics Laboratory Rocket Center, West Virginia Location5: Carpathia Hosting Inc. 43480 Yukon Dr. #200, Ashburn, VA 20147 Location6: 16825 S. Seaton Avenue, Emmitsburg, MD 21727-8998 Location7: 6511 America Boulevard, Hyattsville, MD Location8: 430 Market St. Winchester, VA Location9: 19844 Blue Ridge Mountain Rd. Bluemont, VA http://en.wikipedia.org/wiki/Allegany_Ballistics_Laboratory http://www.google.com/url?sa=t&rct=j&q=&esrc=s&frm=1&source=web&cd=1&cad=rja&ved=0CCkQFjAA&url=http%3A%2F%2Fwww.carpathiahost.com%2F&ei=ZQQFU6r9LYbGkQe7zIH4CQ&usg=AFQjCNEGm0neZjs2VzzsWd2BeO0TaDVN_A&sig2=W17iemgg9akgTTHQyzSCjg&bvm=bv.61535280,d.eW0

Location10: 500 C St. SW Washington, DC 20472

MERS, NIPSC, Logistic Centers Location: Various US Locations

5.0 CERTIFICATIONS

If you find a dead link or we are missing a certification vendor, please use our contact form and let us know.

Certification Links Adobe Adobe Certified Associate (ACA)

Adobe Certified Expert (ACE) Adobe Certified Instructor (ACI)

Adtran Internetworking Certifications IP Telephony Certifications Unified Communications Certifications

AIIM Certified Information Professional (CIP) Alcatel-Lucent Alcatel-Lucent Network Routing Specialist I (NRS I)

Alcatel-Lucent Network Routing Specialist II (NRS II) Alcatel-Lucent Triple Play Routing Professional (3RP) Alcatel-Lucent Service Routing Architect (SRA)

American Society for Quality Variety of quality related certs

Apple Certifications for Creative Professionals Certifications for IT Professionals Certifications for Business Certifications for Education

ARM ARM Accredited Engineer Program

BICSI Various Certifications

BMC Software BMC Software certifications

Certified E-commerce Consultants

Project Manager E-Business Certification (PME) Certified E-Marketing Analyst Certification (CEA) Master Project Manager Certification (MPM) Software Analyst Certification (CSA)

Check Point Software Check Point Certifications

Cisco Systems List of Cisco Certifications

Citrix Citrix certifications

CIW Certified Internet Webmaster certifications

CompTCyber Security A+ Certified Document Imaging Architect (CDCyber Security+) Certified Technical Trainer (CTT+) Convergence+ Digital Home Technology Integrator (DHTI+) Linux+ Network+

PDI+

Project+

RFID+

Security+ Server+ http://www.adobe.com/education/instruction/ace/ http://www.adobe.com/education/instruction/ace/ http://www.adobe.com/support/certification/aci.html%23_blank http://www.adtran.com/web/page/portal/Adtran/wp_certifications_internetworking http://www.adtran.com/web/page/portal/Adtran/wp_certifications_iptelephony http://www.adtran.com/web/page/portal/Adtran/wp_certifications_unifiedcommunications%23_blank http://www.aiim.org/Training/Certification http://www.alcatel-lucent.com/wps/portal/src http://www.alcatel-lucent.com/wps/portal/src http://www.alcatel-lucent.com/wps/portal/src http://www.alcatel-lucent.com/wps/portal/src http://www.asq.org/certification/right-for-you.html http://training.apple.com/%23creative http://training.apple.com/%23it http://training.apple.com/%23business http://training.apple.com/%23education http://www.arm.com/support/arm-accredited-engineer/ https://www.bicsi.org/credential_programs.aspx http://www.bmc.com/education/certification-programs http://www.icecc.com/pme.html http://www.icecc.com/cimm.html http://www.projectmanagementcertification.org/ http://www.icecc.com/csa.html http://www.checkpoint.com/products/certifications/index.html http://www.cisco.com/web/learning/le3/learning_career_certifications_and_learning_paths_home.html http://www.citrixtraining.com/courses/certifications/index.cfm http://www.ciwcertified.com/%23_blank http://www.comptia.org/certifications/listed/a.aspx http://www.comptia.org/certifications/listed/cdia.aspx http://www.comptia.org/certifications/listed/ctt.aspx http://www.comptia.org/certifications/listed/convergence.aspx http://www.comptia.org/certifications/listed/dhti.aspx http://www.comptia.org/certifications/listed/linux.aspx http://www.comptia.org/certifications/listed/network.aspx http://www.comptia.org/certifications/listed/linux.aspx http://www.comptia.org/certifications/listed/project.aspx http://www.comptia.org/certifications/listed/rfid.aspx http://www.comptia.org/certifications/listed/security.aspx http://www.comptia.org/certifications/listed/server.aspx

Certification Links Computer Associates International

Product Accreditations

DSDM Secretariat Dynamic Systems Development Method certifications EC-Council CEH, CHFI, ECSA, CNDA, LPT, ECVP, ECSP, etc.

Enterasys Systems Enterasys Systems Engineer (ESE) Enterasys Security Systems Engineer-IPS/SIEM (ESSE-IPS/SIEM) Enterasys Security Systems Engineer-NAC (ESSE-NAC) Enterasys Certified Internetworking Engineer (ECIE)

ExpertRating Dozens of certifications covering Windows, programming, networking, databases and much more.

GIAC Several certifications covering security, forensics, auditing, management, and legal topics.

Green Computing Initiative GCI User Specialist, GCI Professional, GCI Architect

H3C H3C Certifications

HDI HDI certifications

Hewlett Packard Tons of certs

Holistic Information Security Practitioner Institute

Holistic Information Security Practitioner (HISP)

IEEE Computer Society Certified Software Development Associate (CSDA) Certified Software Development Professional (CSDA)

IBM Corporation IBM certifications

Infinidox Information Security Engineering Certified Professional Information Security Management Certified Professional Information Security Auditing Certified Professional Network and Internet Security Specialist Cryptography Specialist UNIX Security Specialist Solaris Security Specialist AIX Security Specialist HP-UX Security Specialist Linux Security Specialist Windows Security Specialist CISCO Security Specialist

Information Systems Audit and Control Association (ISACA)

Certified Information Systems Auditor (CISA) Certified Information Security Manager (CISM) Certified in the Governance of Enterprise IT (CGEIT) Certified in Risk and Information Systems Control (CRISC)

Institute for Certification of Computing Professionals (ICCP)

ACP, CBIP, CCP, CDMP, ISA, I.S.P.

Institute for Configuration Management

CMIIB, CMIIC, CMIIS, CMICyber Security, CMIIP

Institute for Interconnecting & Packaging Electronic Circuits

Various certification programs

Institute of Electrical and Electronics Engineers (IEEE)

Certified Software Development Associate (CSDA) Certified Software Development Professional (CSDP)

International Function Point Users Group

Certified Function Point Specialist (CFPS) Certified Software Measurement Specialist (CSMS)

International Society of Certified Electronics Technicians (ISCET)

ISCET Certifications http://www.ca.com/us/education/content.aspx?cid=133345 http://www.dsdm.org/certification/default.asp https://cert.eccouncil.org/ http://www.enterasys.com/services-training/certifications/systems-engineer.aspx http://www.enterasys.com/services-training/certifications/security-systems-engineer-dragon.aspx http://www.enterasys.com/services-training/certifications/security-systems-engineer-nac.aspx http://www.enterasys.com/services-training/certifications/certified-internetworking-engineer.aspx http://www.expertrating.com/examlist.asp?affid=104 http://www.giac.org/certifications http://www.greenci.org/ http://www.h3c.com/portal/Training___Certification/Certification/Certification_System/ http://www.thinkhdi.com/hdi.aspx?c=563%23_blank http://www.hp.com/education/index.html%23_blank http://www.hispi.org/certification.php%23_blank…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .