PWS6a-Information_System_Security_Officer_v5.pdf
PDF 594 KB Posted
- Attached to
- FEMA INFORMATION TECHNOLOGY INDUSTRY DAY Federal contract opportunity
- Solicitation number
- HSFE30-15-S-0001
About this file
PWS -Information System Security Officer
View the file
Other files for this federal contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PROCUREMENT SENSITIVE
6A – Information Technology Security SOW
Information
System Security Officer Support
Statement of Work ii
INTENTIONALLY LEFT BLANK
iii
Table of Contents
1.0 Introduction
1.1 Scope
1.2 Background/Current Contract Environment
1.3 Objectives
1.4 Applicable Documents
2.0 Specific Tasks
2.1 Task 1 – Program and Project Management
2.2 Task 2 – Information System Security Officer Contractor Support
2.3 Task 3 - Senior Technical Writer Support
2.4 Task 4 – Adhoc and Surge Requirements
3.0 Deliverables
4.0 Work Schedule
5.0 Place of Performance
5.1 Project Management
5.2 Information System Security Officer
6.0 Contractor Experience Requirements – Key Personnel
7.0 Government Furnished Information And Equipment
8.0 Contractor Furnished Equipment
9.0 Safeguarding of Sensitive Information
10.0 Information Technology Security and PRIVACY TRAINING
11.0 Accessibility Requirements (Section 508)
11.1 Section 508 Applicable EIT Accessibility Standards
11.2 Section 508 Applicable Exceptions
11.3 Section 508 Compliance Requirements
12.0 Other Considerations
12.1 Travel Requirements
12.2 Inspection and Acceptance
12.3 Operating Constraints
Appenix A. Performance Based Matrix iv
1.0 INTRODUCTION
FEMA’s Chief Information System Officer (CISO) and staff is responsible for developing a comprehensive management approach for ensuring compliance with the Federal legislation, regulation and guidelines, departmental policies and procedures as well as ensuring information systems operate at an acceptable risk based on the required mode of operations.
The CISO serves Division Chief of the Office of Cyber Security (OCS) and reports directly to the FEMA Chief Information Officer (CIO).
OCS functions as FEMA’s principal office for cyber security management, oversight, and issue resolution. The office oversees FEMA’s Cyber Security Program by managing and controlling all aspects of security vulnerabilities, including conducting incident investigation, diagnosis, resolution, recovery, and closure, as well as establishing and maintaining security education and training programs.
1.1 Scope
OCS will utilize this contract vehicle to obtain experienced, talented, and highly skilled certified technical cyber security professionals to serve as ISSOs and subject matter experts (SMEs) for various FEMA systems. This contract contains –
• Information System Security Officer (ISSO) Program and Project Management support;
• ISSO Contractor Support, to include consulting services; and
• ISSO Adhoc and Surge Requirement.
The Offeror shall provide the expertise, technical knowledge, staff support, and other related resources necessary to:
• Perform analysis to ensure security controls are consistently implemented;
• Integrate new technology with Cyber Security standards;
• Develop and execute plans for monitoring, assessing, and verifying security controls across all major information systems; and
• Develop, evaluate, and exercise IT survivability and contingency plans.
1.2 Background/Current Contract Environment
OCS provides cyber support to FEMA’s emergency management and continuity mission by utilizing the Federal Cyber Security Framework, in order to
• Identify risks to systems, assets, data, and capabilities;
• Protect mission essential and critical services;
• Detect cybersecurity events;
• Respond to detected cybersecurity events; and
• Recover capabilities or services that were impaired due to a cybersecurity event.
OCS plans, coordinates, integrates, synchronizes, and conducts activities that lead day-to-day safeguarding and protection of FEMA information systems (directly and indirectly connected to the FEMA infrastructure). At a minimum, OCS supports information within the continental United States (CONUS) and outside the continental United States (OCONUS). These information systems may reside at, but not limited to, the FEMA Headquarters (within the National Capital Region); the 10 Regional Offices (Boston, New York, Philadelphia, Atlanta, Chicago, Denton, Kansas City, Denver, Oakland, and Seattle); 8 Distribution Centers [Moffett, Guam, Hawaii, Fort Worth, Caribbean, Atlanta, Disaster Information System Clearinghouse (DISC), Fredrick]; various Disaster Emergency Communications facilities; and Contractor Owned and Contractor Operated (COCO) facilities.
The Top Technology challenges are face by OCS are:
1. Resiliency – Resilient Architecture and Operations
2. Automated Risk Detection-monitoring Heuristic/Behavioral - Large scale/Real-time/Multi-domain
3. Automated Risk Mitigation
4. Usability – Transparent Security
5. Cloud - Store Sensitive Government Data Searchable and Usable on Public Clouds
6. Detection and Response Mechanisms for Insiders (Timely, Fine-grained)
7. Leverage Classified Knowledge/Signatures in a Host-based System
8. Mobility - Hardware RoT, SEAndroid, Secure boot, Secure Baseband
9. Security for Cloud User Environments – Thick/Thin Client, Virtualization
10. Engineering, Testing, and Operating Secure Composite Systems
11. Establishing and Maintaining Assurance in Heterogeneous, Mobile and Cloud
Environments
FEMA’s mission is to reduce the loss of life and property and protect communities nationwide from all hazards, including natural disasters, acts of terrorism, and other manmade disasters.
FEMA leads and supports the nation in a risk-based, comprehensive emergency management system of preparedness, response, recovery, assistance, and mitigation. In support of this mission, FEMA uses a wide variety of information systems and information technology (IT) solutions and services. These systems, solutions, and services must be operated and maintained at the highest level of confidentiality, availability, and integrity.
OCS will provide oversight and management of the work and tasks orders under this Statement of Work. The mission of the FEMA OCIO is “to enhance and maintain IT infrastructure; develop and enhance key systems to support operating programs; increase efficiencies and cooperation across FEMA’s divisional and regional lines.” The vision and strategy of the OCIO is to modernize FEMA IT systems and services and to “deliver world-class secure IT guidance, products, and services to meet the needs of FEMA’s emergency managers and stakeholders nationwide.” The environment must be implemented with the flexibility required to support http://en.wiktionary.org/wiki/continental_United_States http://en.wiktionary.org/wiki/continental_United_States http://en.wiktionary.org/wiki/continental_United_States the evolving mission of FEMA and to support the surge requirements necessary to support emergency situations as they occur.
Currently, FEMA’s IT environment is an amalgam of new and legacy technologies, architectures, platforms, and tools that includes a wide variety of PC-based, client-server, web-based, mobile technology, and service-oriented components. The IT systems supporting FEMA’s are implemented using a variety of service providers under both mature and immature oversight and governance conditions. As stated above, the current goals are to continue the evolution and improvement of all IT services and support. The OCIO goal will be achieved by utilizing an approach and strategy that is consistent with both the Department of Homeland Security (DHS) and FEMA strategy.
1.3 Objectives
The following are objectives of FEMA’s Cyber Security Program:
• Perform gap analysis on current security infrastructure
• Ensure consistent application of information security standards across all agency information systems.
• Meet all regulatory and agency documented standards and guidance.
• Integrate these regulations and standards into a fully implementable security program.
• Ensure preparation for internal and external audits through management of all infrastructure artifacts required to pass audits.
• Ensure all new information technology (IT) projects meet or integrate security standards into their development.
• Develop a culture of security-mindful professionals across the community.
• Strive to be more flexible and responsive to new regulatory directives.
• Serve as the central authority for all Cyber Security-related activities across the agency.
• Ensure information system survivability and integrity.
• Optimize processes to meet Cyber Security-related goals and strategies
1.4 Applicable Documents
This section contains a list, but not limited to, applicable references utilized by OCS –
• National Institute of Standards and Technology (NIST), Special Publication (SP) 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems— A Security Life Cycle Approach, February 2010
• NIST SP 800-39, Managing Information Security Risk—Organization, Mission, and Information System View, March 2011
• NIST SP 500-53, Security and Privacy Controls for Federal Information Systems and Organizations
• NIST SP 500-53, Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans
• NIST SP 800-65, Integrating Cyber Security into the Capital Planning and Investment Control Process, dated January 2005
• 4300A Sensitive Systems Policy -- Version 11.0
• 4300A Sensitive Systems Policy Handbook -- Version 9.1 o Attachment B - Waivers Request Form -- Version 11 o Attachment C - ISSO Letter -- Version 11 o Attachment D - Type Accreditation -- Version 11 o Attachment E - FISMA Reporting -- Version11 o Attachment F - Incident Response -- Version 9.1 o Attachment G - Rules of Behavior -- Version 11 o Attachment H - POAM Process Guide -- UNDER REVISIONS -- Version 9.1 o Attachment I - Workstation Logon o Attachment K - IT Contingency Plan Template -- Version 11 o Attachment L - Password Management o Attachment M - 800-53 Controls -- Version11 o Attachment N - Interconnection Security Agreements -- Version 11 o Attachment O - Vulnerability Management -- Version 9.1 o Attachment P - Document Change Requests -- Version 11 o Attachment Q1 - Wireless Systems --Version 11 o Attachment Q2 - Mobile Devices -- Version 11 o Attachment Q3 - Tactical Systems o Attachment Q4 - RFID Systems -- Version 11 o Attachment R - Compliance Framework Guide -- Version 9.1 o Attachment S - Compliance Framework for Privacy Systems -- UNDER REVISIONS
-- Version 9.1 o Attachment S1 - Managing CREs containing SPII -- UNDER REVISIONS -- Version
9.1 o Attachment T - Acronyms o Attachment X - Social Media -- UNDER REVISIONS
• 4300B National Security System Policy Cover Page - Version 9.0
• 4300B National Security Systems Table of Contents - Version 9.0
• 4300B.100: Safeguarding and Risk Management for NSS
• 4300B.101 Risk Management for NSS
• 4300B.102 National Security System Security Control Guidance
• 4300B.103 Template Guidance o 4300B.103-1 Template for System Security Plans o 4300B.103-2 Template for Risk Assessment Reports o 4300B.103-3 Template for Security Assessment Reports o 4300B.103-4 Template for Plans of Action and Milestones
• 4300B.106 DHS NSS General and Privilege User Account Request Minimum Requirements
• 4300B.107 Decommissioning Strategy Minimum Requirements http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Policy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Handbook.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20B%5d%20Waiver%20Request%20Form.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20C%5d%20ISSO%20Letter.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20D%5d%20%20Type%20Accreditation.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20E%5d%20FISMA%20Reporting.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20F%5dIncident%20Response.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20G%5d%20%20Rules%20of%20Behavior.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20H%5dPOAM%20Guide.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20I%5dWorkstation%20Logon.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20K%5d%20%20IT%20Contingency%20Plan%20Template.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20L%5dPassword%20Management.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20M%5d%20Tailoring%20NIST%20800-53%20Security%20Ctrls.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20N%5d%20Interconnection%20Security%20Agreements.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20O%5dVulnerability%20Management.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20P%5d%20Document%20Change%20Requests.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q1%5d%20Sensitive%20Wireless%20Systems.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q2%5d%20Mobile%20Devices-CLEAN%20DRAFT.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q3%5dTactical%20Systems.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q4%5d%20Sensitive%20RFID%20Systems.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20R%5dCompli%20Fmwk%20CFO-designated%20Systems.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20S%5dCompliance%20Framework%20for%20Privacy%20Systems.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20S1%5dManaging%20CREs%20Containing%20SPII.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20T%5dAcronyms.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.000%20National%20Security%20Systems%20Policy%20Coverpage.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.000_TOC_4300B_05102013.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.100%20-%20Safeguarding%20and%20Risk%20Mgmt%20for%20NSS.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.100%20-%20Safeguarding%20and%20Risk%20Mgmt%20for%20NSS.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.101%20-%20Risk%20Management%20Framework.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.101%20-%20Risk%20Management%20Framework.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.102%20-%20NSS%20Security%20Control%20Guidance%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.102%20-%20NSS%20Security%20Control%20Guidance%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-1%20-%20System%20Security%20Plans%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-1%20-%20System%20Security%20Plans%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103.2%20-%20Risk%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103.2%20-%20Risk%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-3%20-%20Security%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-3%20-%20Security%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-4%20-%20Plans%20of%20Action%20and%20Milestones.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-4%20-%20Plans%20of%20Action%20and%20Milestones.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.107%20-%20Decommissioning%20Strategy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.107%20-%20Decommissioning%20Strategy.pdf
• 4300B.108-1 National Security System References
• 4300B.108-2 National Security System Policy Change Request
• 4300B.200 Communication Security (COMSEC) - Version 2.0
• DHS Ongoing Authorization Methodology
• DHS CISO NIST SP 800-53 Security Controls tri-fold
• DHS FISMA System Inventory Methodology
• DHS Information Security Performance Plan
• DHS Security Authorization Process Guide
• DHS Document Review Methodology
• Document Review Checklists
• Security Authorization Document Templates
• FIPS-199 Workbook and Instructions
• Privacy Threshold Analysis (PTA) Template
2.0 SPECIFIC TASKS
2.1 Task 1 – Program and Project Management
The Offeror shall provide program management support to OCS. The Program Manager shall be onsite Monday – Friday during core hours (0800 until 1700 hours). The Program Manager shall report directly to the Contracting Officer Representative. Such responsibilities shall include provide centralized assistance with the coordination management of the FEMA ISSO program
The Program Manager shall server as the Project Manager responsible for OCS ISSO projects that are temporary and produce a unique product, service or result. ISSO tasks and activities executed within the OCS are treated as projects. All ISSO Project Management services shall adhere to the PMI Project Management framework for project planning, scheduling, communications, reporting, and contractual activity and to ensure that any technical issues are addressed quickly and professionally.
The Offeror’s Project Manager shall be responsible for the Project Planning and Project Management aspects of this task. This task continues for the entire duration of the project.
This task includes the regularly scheduled meetings and specified documentation; i.e., Weekly Status Meeting, Weekly Status Reports, Weekly Work, Plan Review, Schedule Review, and Oversight/Stakeholder Reporting.
The Offeror shall develop a Project Management Plan (PMP) successful execution of the tasks within this SOW. The PMP shall to manage, schedule, and track progress using Microsoft (MS) Project or agreed upon medium (e.g., SharePoint). The current progress information shall be provided to the Government through contractor management meetings, monthly activity reports, and MS Project files. The PMP shall – http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.108-1%20-%20NSS%20References.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.108.2%20-%20NSS%20Policy%20Change%20Request.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.200%20COMSEC.pdf
• Provide leadership, management, and administrative support for contractor work in support of Cyber Operations. Specific activities include but are not limited to the following:
• Provide overall management and oversight of contract staff and activities to ensure all work comply with applicable DHS, FEMA, and OCIO policies and regulations; ensure contractor performance is timely and meets OCIO/CISO program goals and performance standards
• Provide overall technical leadership and oversight; recommend and oversee the implementation of proactive and leading edge technical and technological approaches and solutions to address emerging cyber security trends; report on an annual basis
• Provide administrative support for contract work activities to include support Cyber Operations; prepare memorandums and correspondence; perform filing, passing of clearances, meeting and conference coordination, and other office administration duties
• Provide and finalize the Program Management Plan within 20 business days of contract start date.
• Provide and finalize individual Task Management Plan that addresses at a minimum, performance schedule, milestones, deliverables, and approaches to problem resolution and communication and coordination with Government personnel within 20 business days of contract start
• Provide and finalize GFE Inventory Management Procedures within 20 business days of contract start
• Monitor and track program and task performance to ensure on time service delivery within established cost estimates
• Identify, recommend, and implement (upon Government approval) cost-saving measures
• Provide monthly Task Status Report for each task (to the designated Government Technical Monitor) by the 15th of each month, presenting:
o Activities and milestones completed and deliverables submitted for each task for the past month o Indication of potential schedule variance, mitigation strategies, and actions taken o Issues encountered and resolution applied o Issues unresolved and current status and actions o Milestones and activities planned for the next reporting period
• Provide monthly Program Status Report (to the Contracting Officer’s Representative) by the 15th of each month, incorporating the Task Status Reports and the following for the overall program:
o Updated of the SOW Plan of Action and Milestones (POA&M) schedule (originally delivered as part of the PMP) including milestones achieved and schedule changes o Funding expended and funding remaining o A copy of deliverables submitted to the government for acceptance o Program risks identified and mitigation action taken and planned o A narrative of management or technical problems o Suggestions and Recommendations o A projected schedule for next month’s activities o A report of all activities during travel, in a format specified by the Contracting
Officer’s Representative (COR).
o Total cost incurred in the past month and fiscal year-to-date o Indication of potential cost and/or schedule variance, mitigation strategies, and actions taken o Funding and expenditure status o Staffing status to include current staffing level (%); positions open/unfilled and number of days open/unfilled o Cost saving measures implementation status including activities and milestones completed and planned
• Conduct Program and individual Task Status Review monthly, as requested by the
Program Manager and/or COR, to provide opportunity for report clarification and issue resolution
• Prepare and conduct quarterly Program Performance Reviews (IAW Quality Assurance Surveillance Plan) to include identification of potential cost saving measures in each task area and related implementation plans and status
• Support acquisition of materials and services incidental to contractor work activities
The Offeror shall develop and submit the following management controls reports:
• Contract Management Meetings,
• Use of Automated Tools, and
• Quality Control (QC) and Quality Assurance (QA) Procedures.
2.1.1.1 Regular Contractor Management Meetings
The Offeror and FEMA shall hold regularly scheduled monthly Contractor Management Meetings. The meeting shall provide the government and the Offeror an opportunity to discuss current tasking, provide additional guidance to the technical task management of the contract, and give the Offeror an opportunity to ask questions pertinent to the successful completion of the task.
2.1.1.2 Quality Control and Quality Assurance Procedures
Quality of data is paramount importance to the FEMA. The Offeror plays a critical role in establishing and maintaining the quality of the program. The Offeror shall perform the following:
• Data Collection Quality Control (QC) – The Offeror shall develop and implement a written QC program for data collection to ensure compliance with DHS and FEMA processes and procedures.
• Data Quality Assurance (QA) – The Offeror shall support and participate in the DHS QA review program as defined by the requirements of Contractors QA Procedures. The Offeror shall provide propose corrective actions to the COR to address any minor deficiencies identified in the review within five working days of receiving the QA report.
If the Offeror receives an unacceptable QA rating, FEMA may suspend the Offeror’s activities, by written notice from the Contracting Officer (CO) until acceptable adjustments have been implemented and an acceptable QA is earned by the Offeror.
2.2 Task 2 – Information System Security Officer Contractor Support DHS policy requires the Information System Security Officer (ISSO) be appointment to every information system. The Offeror shall provide qualified, proficient, and certified security professional to serve as contractor ISSOs and SME. These personnel shall be designated as key personnel. Key personnel shall be approved by the CISO and COR prior to onboarding. The ISSO shall serve as the point of contact (POC) for all security and technical matters related to their assigned system. Once appointed by the CISO, the ISSO shall study and be familiar with the following documentation:
• DHS System Policies and Handbooks (DHS Directive 4300A or 4300B)
• DHS Security Authorization Guide
• DHS ISSO Guide
• DHS Information Security Performance Plan
• FEMA Directive 140-1 as well as other relevant security policy
The Offeror shall provide the COR with the designee’s resume and summarization of the candidate ability to meet the experience requirements for the ISSO position, which is outlined within the OCS Cyber Security Workforce Improvement Plan. The plan is reviewed and update annual. The Offeror shall be expected to meet the annual requirements outline within the improvement plan. In addition, the Offeror shall provide DHS ISSO/AISSO Roles and Acknowledgement as well as a Non-Disclosure Agreement for each candidate approved to star on Day 1.
ISSOs are official appointed by the CISO and designated by the System Owner to ensure FEMA’s information system are operating and maintained FEMA’s information system or information systems at the appropriate operational. ISSOs assists in identifying, implementing, and assessing the common security controls; and actively supporting the development and maintenance of the security plan, to include coordinating system changes with the information system owner and assessing the security impact of those changes. ISSOs shall serve as Technical Advisor’s to the CISO and System Owner on all areas of cyber security and as such, responsible for:
• Maintaining ongoing knowledge: (a) of Federal legislation, regulation, policies, and practices related to cyber security; (b) methodologies and best practices that are commonly used in the cyber security industry; (c) the status of Federal Cyber Security initiatives; (d) automation architectures used at FEMA; (e) COTS software packages;
custom developed software applications; and network and telecommunications products and technologies; and, (f) the threats to and vulnerabilities.
• Recommending courses of action and policies to senior management that allow FEMA to securely meet the organizational goals.
• Managing the monitoring and recording the performance of cyber security initiatives for FEMA and regularly reporting its status to the AO, DAO, CISO, ISSM and SO. The ISSO prepared to report and memorandum of records regarding the cyber security status of their assigned system for FEMA leadership review and signature.
OMB Circular A-130 requires all Information system or information systems to be authorized in accordance with the National Institute Standards and Technology (NIST) guidelines and standards. DHS security authorization process for certifying and accrediting an information systems complies with the guidelines and standards published by NIST. ISSOs shall devise a plan to certify and accredit their assigned Information system or information systems. ISSOs shall ensure their assigned Information system or information systems receives a favorable authorization decision by ensuring all required security authorization artifacts are developed and maintained in accordance with DHS and FEMA standards. ISSOs shall adhere to guidelines and standards defined within the current year Security Authorization Guide and the DHS Information Security Performance Plan.
Specific objectives associated with the artifacts of each security authorization package are delineated below:
• Federal Information Processing Standards Publications 199
• Risk Assessment
• Privacy Threshold Assessment
• Privacy Impact Assessment (if required)
• Security Plan
• Contingency Plan
• Security Control Testing Support
• Plan of Action and Milestone (POA&M)
• Standard Operation Procedures
• System Specific Policies
The Contractor ISSO shall assist the CISO, System Owners, and System/Database Administrators with maintaining the security posture of their assigned information system or information systems. The Offeror shall provide cyber security professions that meet or exceeds the security labor categories. The Offeror shall provide personnel with extensive knowledge and hands on experience the following areas:
• Security Fundamentals - Defense-in-Depth
• Data classification and labeling
• Regulations, Legislation and Guidance
• Firewalls and Intrusion Protection/Detection Systems
• Network (VLANS, VPNS, wireless, etc.)
• Communication media (telecommunication), protocols, and services
• Encryption
• Risk and Threat Management
• Vulnerability Assessment and Management
• Incident Response
• Audit Log Review
• Operating Systems (Window, LINUX, etc.)
• Database (SQL, Oracle, etc.)
• Content Management
• Hardening of servers and mobile devices (laptops, iPhones, Android devices, etc.)
• Hardening of network appliances and devices
The Contractor ISSO shall support all activities that ensure the level of security documented with the security authorization is maintained. Activities can include, but not limited to, the following:
• Monitoring the status of POA&Ms to ensure weaknesses are resolved;
• Conducting an annual assessment in accordance with guidance in the DHS Information
Security Performance Plan;
• Reviewing and updating security authorization documents as needed, but at least annually;
• Conducting Contingency Plan tests at least annually and updating the plan;
• Conducting periodic scans of the system to ensure the configuration remains compliant with DHS guidance;
• Ensuring CM processes are followed to ensure that any changes do not introduce new security risks;
• Providing weekly incident response reports to the FEMA Security Operations Center
(SOC); and
• Working with Certification Agents on a regular basis (daily, weekly, and/or monthly)
The Contractor ISSO must be able to provide support throughout the United States (CONUS and OCONUS). In addition, the Offeror must be able to support FEMA’s disaster operations during a disaster declaration or an emergency.
The Contractor ISSO shall provide consulting services for this task to the government.
2.3 Task 3 - Senior Technical Writer Support
The Technical Writer will be tasks by the CISO or designee to review documentation as required for submittal to internal, external customers. Ensure documentation meets FEMA Correspondence Policy, and Branding Standards if required. Ensure documents are reviewed in a timeline that is acceptable to Management including weekly status as a minimum. Maintain and update as required all Cyber Security documentation as directed by COR, or designee.
The Offeror shall provide consulting services for this task to the government.
2.4 Task 4 – Adhoc and Surge Requirements
The Offeror upon request from the Contracting Officer (CO) and COR shall provide Contractor ISSO to meet adhoc and surge requirements. Within the scope of this requirement, adhoc and surge requirements will most certainly arise during the life of this contract. These situations will require the Offeror to respond with very little notice. Since response to these emergencies will not allow time to identify additional personnel, the Offeror’s personnel performing on current tasks will be diverted to these emergency requirements. If these requirements become prolonged, the Offeror may be requested to backfill personnel for various tasks to replace the personnel that have been diverted. Any changes to the tasks will be dealt with through the Changes Clause.
3.0 DELIVERABLES
This section list deliverables identified within Section 2.
The Offeror shall deliverables electronically using an agreed upon format. Electronic submission shall be made via email, unless otherwise agreed to by the COR.
SOW TASK
# DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS
2.1. TASK 1 - PROJECT MANAGEMENT
2.1 Task 1 – Project Management Plan Contractor-
Determined Format Standard Distribution TBD after task award
2.1 Task 1 – Weekly Activity Reports Contractor-
Determined Format
2.1 Task 1 – Monthly Activity Reports Contractor-
2.1 Task 1 – Program Status Reports Contractor-
2.1 Task 1 – Project Schedules (includes Integrated Master
Schedule)
Contractor- Determined Format
2.1 Task 1 - GFE Inventory Management Procedures Contractor-
2.1 Task 1 - Program Performance Reviews Contractor-
2.1 Task 1 – Task POA&M Contractor-
2.1 Task 1 – Management Controls Reports Contractor-
2.1 Task 1 – Meeting Minutes Contractor-
2.1 Task 1 – Travel Reports Contractor-
Monthly Performance and Progress Report Contractor-
Standard Distribution Monthly NLT 10th of each Reporting period
Program management plan Contractor- Determined Format
Standard Distribution TBD after task award
NLT 15 calendar DACA and updates as requested by COR
Quality Assurance Plan (QAP) Contractor- Determined Format
Standard Distribution TBD after task award
NLT 15 calendar DACA and updates as requested by COR
Monthly Performance and Progress Report Contractor- Determined Format
Standard Distribution TBD after task award
NLT 10th of each reporting period.
# DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS
Program management plan Contractor- Determined Format
Standard Distribution TBD after task award
NLT 15 calendar DACA and updates as requested by COR
Quality Assurance Plan (QAP) Contractor- Determined Format
Standard Distribution TBD after task award
NLT 15 calendar DACA and updates as requested by COR
In-briefs and Out-briefs Contractor- Determined Format
2.2 Task 2 – ISSO Contractor Support
2.2 Security Authorization documentation To be identified at
award Standard Distribution 60 days prior going operational or the expiration of an authorization decision
Risk Assessment Report To be identified at
Standard Distribution All changes and releases
Contingency Test Report To be identified at
Standard Distribution Annually
Non-Disclosure Agreement To be identified at award
Standard Distribution Annually Signed statements are due, from each employee assigned, prior to performing ANY work on this task.
ISSO Resumes To be identified at award
ISSO Acknowledgement of Responsibilities To be identified at
Security C&A Phase 1 package reviews To be identified at
Standard Distribution TBD after task award
Deliverables are provided within agreed upon project plan timeframe
C&A package revisions including required revisions in IACS or C-TAF
To be identified at award
Standard Distribution TBD after task award
Deliverables are provided within agreed upon project plan timeframe
# DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS
IACS or C-TAF Compliance descriptions in IACS or C-TAF To be identified at award
Standard Distribution TBD after task award
Deliverables are provided within agreed upon project plan timeframe
Security Metrics Recommendations To be identified at award
Standard Distribution TBD after task award
Final recommendation developed within 120 calendar DACA
Security Communications Plan To be identified at award
Standard Distribution TBD after task award
Final Plan developed within 90 calendar DACA
Procedure TRAINING Program To be identified at award
Standard Distribution TBD after task award
Final Program Plan developed within 180 calendar DACA
Vulnerability Testing and Scanning Report, Server configuration change report
To be identified at award
Standard Distribution TBD after task award
Report delivered by 15th of month
Project plan for Security Program Assessment To be identified at award
Standard Distribution TBD after task award
Final Plan developed within 60 calendar days of optional task order award
Security Program Improvement plan implementation To be identified at award
Standard Distribution TBD after task award
Implementation Plan developed within approved project plan timelines
Assessment of FS Centralized Account Management process To be identified at award
Standard Distribution TBD after task award
Final Plan developed within 60 calendar days of optional task order award recommendations for account management improvement To be identified at award
Standard Distribution TBD after task award
Final recommendations due within 120 calendar days of optional task award
Formal evaluation of Technical Approval requests To be identified at award
Standard Distribution TBD after task award
Evaluation submitted within 20 calendar days after receipt of technical approval request
Process improvement recommendations To be identified at award
Standard Distribution TBD after task award
Final recommendations due within 180 calendar days of optional task award
# DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS
Wireless security assessments To be identified at award
Standard Distribution TBD after task award
Final assessment due within 120 calendar days of optional task award
WAN/LAN security assessments To be identified at award
Standard Distribution TBD after task award
Final assessment due within 120 calendar days of optional task award
Weekly interim status reports To be identified at award
Standard Distribution TBD after task award
Report due COB Monday
Self Help Documentation To be identified at award
Standard Distribution TBD after task award
Final documentation due within 60 days of request
In-briefs and Out-briefs To be identified at award
2.14 Task 14 – Adhoc and Surge Requirements
Formal evaluation of Technical Approval requests To be identified at award
Process improvement recommendations To be identified at
In-briefs and Out-briefs To be identified at
4.0 WORK SCHEDULE
The contractor shall provide support during the core business hours (7:30AM to 7:30PM). In addition, the contractor shall observe all U.S. Government Holidays.
The contractor shall be available for after-hour support (to include holidays).
5.0 PLACE OF PERFORMANCE
5.1 Project Management
Primary work site:
FEMA Head Quarters Site National Capital Region Washington, DC
Alternate work sites:
1. Mount Weather Emergency Operations Center (MW EOC)
2. Alternate Security Operations Center site
3. Department of Homeland Security Operations Center
4. FEMA/DHS contracted datacenters
5. Other Government owned or leased site(s)
5.2 Information System Security Officer
The FEMA Stakeholder Office Location will determine the work site. The site locations are and not limited to:
FEMA Headquarters Location1: DC Metropolitan Area (DMV) Location2: Brooke Rd. Facility, Winchester, VA Location3: Mt Weather Emergency Assistance Center Location4: Allegany Ballistics Laboratory Rocket Center, West Virginia Location5: Carpathia Hosting Inc. 43480 Yukon Dr. #200, Ashburn, VA 20147 Location6: 16825 S. Seaton Avenue, Emmitsburg, MD 21727-8998 Location7: 6511 America Boulevard, Hyattsville, MD Location8: 430 Market St. Winchester, VA Location9: 19844 Blue Ridge Mountain Rd. Bluemont, VA Location10: 500 C St. SW Washington, DC 20472 http://en.wikipedia.org/wiki/Allegany_Ballistics_Laboratory http://www.google.com/url?sa=t&rct=j&q=&esrc=s&frm=1&source=web&cd=1&cad=rja&ved=0CCkQFjAA&url=http%3A%2F%2Fwww.carpathiahost.com%2F&ei=ZQQFU6r9LYbGkQe7zIH4CQ&usg=AFQjCNEGm0neZjs2VzzsWd2BeO0TaDVN_A&sig2=W17iemgg9akgTTHQyzSCjg&bvm=bv.61535280,d.eW0
MERS, NIPSC, Logistic Centers Location: Various US Locations
Region Frederick MERS Location: 4420 Buckeystown Pike, Frederick, MD 20704
Region I Boston Headquarters, Maynard MERS Locations:
99 High Street, 6th Floor Boston, Massachusetts 02110 65 Old MOCSboro Rd, Maynard, MA 01754
Region II New York Headquarters Locations:
26 Federal Plaza, New York, New York 10278-0002 118-35 Queens Blvd, Forest Hills, NY 11375 11A Clinton Square Rm 741, Albany, NY 11227 NJ SRO 307 Middletown- Lincroft Rd, Middletown, NJ 07748 290 Broadway 29th Floor, New York City, NY 10007 201 State Route 34 South, Colts Neck, NJ 07722 159 COCSos Chardon Ave., Hato Rey, P.R. 00198
Region III Philadelphia Headquarters Locations:
One Independence Mall, 615 Chestnut Street Philadelphia, Pennsylvania 19106-4404 2570 Interstate Dr, Harrisburg, PA 17110
Region IV Atlanta Headquarters, Thomasville MERS Location1: 3003 Chamblee-Tucker Road, Atlanta, Georgia 30341 Location2: 402 South Pinetree Blvd., Thomasville, GA. 31792 Location3: Anniston, AL
Region IX - Oakland Headquarters Locations:
1111 Broadway, Oakland, Ca 94607-4052 75 North Fair Oaks Ave, Pasadena, CA 91103 1301 Clay St. Oakland, CA 94607 3720 Dudley Blvd, McClellan Park, CA 95652
Region V - Chicago Headquarters Locations:
536 S. Clark Street, Chicago, Il 60605 635 New Indian Trail Rd, Aurora, IL 60506
Region VI - Denton Regional Center, MERS, NPSC Locations:
Federal Regional Center 800 N. Loop 288 Denton, Texas 76209-3698 1500 Main, Baton Rouge, LA 70802 1 Seine Ct, New Orleans, LA 70114
Region VII - Kansas City Headquarters Locations:
9221 Ward Parkway, Suite 300, Kansas City, Mo 64114-3372 850 SW Chipman Rd, Suite 500, Lees Summit, MO 64063 2312 E Bannister Rd, Kansas City, MO 64131
Region VIII Denver Headquarters, MERS Location:
Building 710, Box 25267 Denver, Colorado 80225-0267
6.0 CONTRACTOR EXPERIENCE REQUIREMENTS – KEY PERSONNEL
All personnel support this contact shall be designated as Key Personnel and meet or exceed the requirements outline with the Cyber Security Workforce Improvement Plan. All personnel shall require COR approval prior to onboarding. The Offeror agrees that such personnel shall not be removed, diverted, or replaced from work without prior written approval of the COR, CISO or designee and the Contracting Officer.
Any personnel the Offeror offers as substitutes shall have the ability and qualifications equal to or better than the original key personnel that are being replaced. Upon government acceptance of the substitution, this individual shall also be defined as key personnel. Requests to substitute personnel shall be approved by the COR, CISO or OCS designee and the Contracting Officer. All requests for approval of substitutions in personnel shall be submitted to the Contracting Officer within 30 calendar days prior to making any change in key personnel.
The request shall be written and provide a detailed explanation of the circumstances necessitating the proposed substitution. The Offeror shall submit a complete resume for the proposed substitute, any changes to the rate specified in the order (as applicable), and any other information requested by the Contracting Officer needed to approve or disapprove the proposed substitution. The COR, CISO or OCS designee and Contracting Officer will evaluate such requests and promptly notify the Offeror of approval or disapproval thereof in writing.
7.0 GOVERNMENT FURNISHED INFORMATION AND EQUIPMENT
The Government shall provide laptops for all Contractor ISSO. The Offeror shall be responsible for the management and safekeeping of the equipment.
All Government supplied information will remain proprietary to the Government. Additionally, vendor proprietary information supplied as a result of any resulting contract may require the execution of Non-Disclosure Statements between the Contractor and respective vendor.
a. DOD 5220.22M National Industrial Security Program Operating Manual, current publication
b. Contractors Quality Assurance Procedures, current publication
c. Critical Information Act of 2002, current publication
d. DHS Program Architecture Guide (when available)
e. RMD will provide the Contractor with appropriate access to information to accomplish the assigned tasks.
8.0 CONTRACTOR FURNISHED EQUIPMENT
The Offeror shall ensure all Contractor ISSO have mobile phones for after-hour support.
9.0 SAFEGUARDING OF SENSITIVE INFORMATION
(a) Applicability. This clause applies to the Contractor, its subcontractors, and Contractor employees (hereafter referred to collectively as “Contractor”). The Contractor shall insert the substance of this clause in all subcontracts.
(b) Definitions. As used in this clause—
“Personally identifiable information” means information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, either alone, or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth, or mother’s maiden name. The definition of personally identifiable information is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-personally identifiable information can become personally identifiable information whenever additional information is made publicly available—in any medium and from any source—that, combined with other available information, could be used to identify an individual.
Examples of PII include, but are not limited to: name, date of birth, mailing address, telephone number, Social Security number (SSN), email address, zip code, account numbers, certificate/license numbers, vehicle identifiers including license plates, uniform resource locators (URLs), static Internet protocol addresses, biometric identifiers such as fingerprint, voiceprint, iris scan, photographic facial images, or any other unique identifying number or characteristic, and any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.
“Sensitive Information” is defined in HSAR clause 3052.204-71, Contractor Employee Access, as any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. This definition includes the following categories of information:
(1) Protected Critical Infrastructure Information (PCII) as set out in the Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), as amended, the implementing regulations thereto (Title 6, Code of Federal Regulations, Part 29) as amended, the applicable PCII Procedures Manual, as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the PCII Program Manager or his/her designee);
(2) Sensitive Security Information (SSI), as defined in Title 49, Code of Federal Regulations, Part 1520, as amended, “Policies and Procedures of Safeguarding and Control of SSI,” as amended, and any supplementary guidance officially communicated by an authorized official of the Department of Homeland Security (including the Assistant Secretary for the Transportation Security Administration or his/her designee);
(3) Information designated as “For Official Use Only,” which is unclassified information of a sensitive nature and the unauthorized disclosure of which could adversely impact a person’s privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national or homeland security interest; and
(4) Any information that is designated “sensitive” or subject to other controls, safeguards or protections in accordance with subsequently adopted homeland security information handling procedures.
“Sensitive Information Incident” is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access or attempted access of any Government system, Contractor system, or sensitive information.
“Sensitive Personally Identifiable Information (SPII)” is a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Some forms of PII are sensitive as stand-alone elements. Examples of such PII include: Social Security numbers (SSN), driver’s license or state identification number, Alien Registration Numbers (A-number), financial account number, and biometric identifiers such as fingerprint, voiceprint, or iris scan.
Additional examples include any groupings of information that contain an individual’s name or other unique identifier plus one or more of the following elements:
(1) Truncated SSN (such as last 4 digits)
(2) Date of birth (month, day, and year)
(3) Citizenship or immigration status
(4) Ethnic or religious affiliation
(5) Sexual orientation
(6) Criminal History
(7) Medical Information
(8) System authentication information such as mother’s maiden name, account passwords or personal identification numbers (PIN)
Other PII may be “sensitive” depending on its context, such as a list of employees and their performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but is not sensitive.
(c) Authorities. The Contractor shall follow all current versions of Government policies and guidance accessible at www…, or available upon request from the Contracting Officer, including but not limited to:
(1) DHS Management Directive 11042.1 Safeguarding Sensitive But Unclassified (for Official Use Only) Information
(2) DHS Sensitive Systems Policy…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .