Security_Operations_Center_Support.pdf

PDF 741 KB Posted

Attached to
FEMA INFORMATION TECHNOLOGY INDUSTRY DAY Federal contract opportunity
Solicitation number
HSFE30-15-S-0001
Issued by
Federal Emergency Management Agency Mitigation Section

View the file

Other files for this federal contract opportunity

Other files attached to FEMA INFORMATION TECHNOLOGY INDUSTRY DAY, newest first.
File Type Posted
FBO15.pdf PDF
FBO13_(002).pdf PDF
FBO12.pdf PDF
FBO11.pdf PDF
FBO10.pdf PDF
FBO9.pdf PDF
FBO8a.pdf PDF
FBO7replacement_(003).pdf PDF
FBO7_2272017.pdf PDF
FBO6_12202016.pdf PDF
FBO5b_(003).pdf PDF
FBO3_8APR16.pdf PDF
PWS6b-Assessment_and_Authorization_Support_v5.pdf PDF
PWS6d-Emerging_Technology_and_Modernization_Support_v5.pdf PDF
PWS6a-Information_System_Security_Officer_v5.pdf PDF
PWSAPPLICATIONENGINEERING.pdf PDF
PWSOperations_and_Maintenance.pdf PDF
FBO.pdf PDF
PWS6c-Security_Operations_Center_Support_v5.pdf PDF
ITOCIrevised5_(3).pdf PDF
OCISecurity5.pdf PDF
Program_Management_Oversight.pdf PDF
IT_Security.pdf PDF
Application_Development.pdf PDF
Mission_Needs.pdf PDF
QAIVV.pdf PDF
Hardware.pdf PDF
General_or_No_Category.pdf PDF
IT_Industry_Day_Roster_-_December_05_2014.pdf PDF
FEMA_IT_Industry_Day_Final_141205.pdf PDF
FEMA_BPA_Draft__Version_12__4__2014_(3).pdf PDF
O__M_-_DRAFT_SOW_09102014.pdf PDF
PMO_Contract_SOO-Draft_(2).pdf PDF
Application_Development_Engineering_and_Sustainment_Draft_SOW.pdf PDF
Information_System_Security_Officer_Draft_SOW.pdf PDF
Emerging_Technology_and_Modernization_Support_Draft_SOW.pdf PDF
FEMA_BPA_Hardware_Software_Draft.pdf PDF
REQUIREMENTS _ESTIMATES _AND_SCOPE_(RES).pdf PDF
Assessment_and_Authorization_Support_Draft_SOW.pdf PDF
FlyerIndustryDay.pdf PDF
Phased_Contract_Award_Approach_Flyer.pdf PDF
Socioeconomic_Disadvantage_Concerns_Flyer.pdf PDF
OCIO_Procurement_Diagram.pdf PDF
FEMA_Information_Technology_Industry_Day_Agenda.pdf PDF
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PROCUREMENT SENSITIVE

Security Operation Center Support

Statement of Work

Donna Bennett, FEMA CISO

INTENTIONALLY LEFT BLANK

ii

Table of Contents

1.0 Introduction

1.1 Scope

1.2 Background/Current Contract Environment

1.3 Objectives

1.4 Applicable Documents

2.0 Specific Tasks

2.1 Task 1 - Project Management

2.1.1 Background

2.1.2 Clearance Requirement

2.1.3 Mission/Objectives/Goals

2.2 Task 2 - 24x7 Security Operations Center (SOC) Services

2.2.1 Background

2.2.2 Clearance Requirement

2.2.3 Mission/Objectives/Goals

2.3 Task 3 - System/Application Vulnerability and Penetration Testing Support (Internal and External)

2.3.1 Background

2.3.2 Clearance Requirement

2.3.3 Mission/Operations/Goals

2.4 Task 4 – Adhoc and Surge Requirements

2.4.1 Background

2.4.2 Clearance Requirement

2.4.3 Mission/Operations/Goals

3.0 Deliverables

4.0 Place of Performance

4.1 Project Management

4.2 24x7 Security Operations Center Services

4.3 System/Application Vulnerability and Penetration Testing Services

5.0 Certifications

6.0 FEMA NWC - Threat Monitoring Team Information Needs

i

6.1 Priority Intelligence Requirements

6.2 Essential Elements of Information

7.0 Government Furnished Information

8.0 Government Furnished Equipment (GFE)

9.0 Security Requirements

9.1 Access to Classified and Sensitive but Unclassified (SBU) Information

9.2 Employment Eligibility

9.3 Continued Eligibility

9.4 Suitability Determination

9.5 Background Investigations

9.6 Security Management

9.6.1 Information Technology Security Clearance

9.6.2 Information Technology Security Training and Oversight

10.0 Section 508 Compliance

10.1 Section 508 Applicable EIT Accessibility Standards

10.2 Section 508 Applicable Exceptions

10.3 Section 508 Compliance Requirements

11.0 Other Considerations

11.1 Travel Requirements

11.2 Inspection and Acceptance

11.3 Operating Constraints

Appenix A. Performance Based Matrix ii iii

1.0 INTRODUCTION

FEMA’s Chief Information System Officer (CISO) and staff is responsible for developing a comprehensive management approach for ensuring compliance with the Federal legislation, regulation and guidelines, departmental policies and procedures as well as ensuring systems operate at an acceptable risk. The CISO is Division Chief for the Office of Cyber Security (OCS) and reports directly to the FEMA Chief Information Officer (CIO). OCS functions as FEMA’s principal office for cyber security management, oversight, and issue resolution. The oversees FEMA’s Cyber Security Program by managing and controlling all aspects of security vulnerabilities, including conducting incident investigation, diagnosis, resolution, recovery, and closure, as well as establishing and maintaining security education and training programs.

OCS will utilize this contract vehicle for Cyber Security staff augmentation, services, and support

• Project Management provides project management services for OCS tasks and activities

• 24x7 Security Operations Center (SOC) Services that support Response Team, Detection

Team, Protection Team, Sensor Support Team, Advance Technology Team (modernization tools/research lab), and Cyber Intelligence (Threat Management).

• Adhoc and Surge Requirement provide responses to OCS adhoc cyber security requests.

The Offeror shall provide experienced certified security professionals to serve as ISSOs over various FEMA systems.

1.1 Scope

Provide the expertise, technical knowledge, staff support, and other related resources necessary to:

• Perform analysis to ensure security controls are consistently implemented.

• Integrate new technology with Cyber Security standards.

• Develop and execute plans for monitoring, assessing, and verifying security controls across all major information systems.

• Develop, evaluate, and exercise IT survivability and contingency plans.

1.2 Background/Current Contract Environment

OCS provides cyber support to FEMA’s emergency management and continuity mission by utilizing the Federal Cyber Security Framework, in order to

• Identify risks to systems, assets, data, and capabilities;

• Protect mission essential and critical services;

• Detect cybersecurity events;

• Respond to detected cybersecurity events; and

• Recover capabilities or services that were impaired due to a cybersecurity event.

OCS plans, coordinates, integrates, synchronizes, and conducts activities that lead day-to-day safeguarding and protection of FEMA information systems (directly and indirectly connected to the FEMA infrastructure). At a minimum, OCS supports information within the continental United States (CONUS) and outside the continental United States (OCONUS). These systems may reside at the FEMA Headquarter within the National Capital Region; the 10 Regional Offices; 8 Distribution Centers, and the various Disaster Emergency Communications facilities.

The Top Technology challenges are face by OCS are:

1. Resiliency – Resilient Architecture and Operations

2. Automated Risk Detection-monitoring Heuristic/Behavioral - Large scale/Real-time/Multi-domain

3. Automated Risk Mitigation

4. Usability – Transparent Security

5. Cloud - Store Sensitive Government Data Searchable and Usable on Public Clouds

6. Detection and Response Mechanisms for Insiders (Timely, Fine-grained)

7. Leverage Classified Knowledge/Signatures in a Host-based System

8. Mobility - Hardware RoT, SEAndroid, Secure boot, Secure Baseband

9. Security for Cloud User Environments – Thick/Thin Client, Virtualization

10. Engineering, Testing, and Operating Secure Composite Systems

11. Establishing and Maintaining Assurance in Heterogeneous, Mobile and Cloud

Environments

FEMA’s mission is to reduce the loss of life and property and protect communities nationwide from all hazards, including natural disasters, acts of terrorism, and other manmade disasters.

FEMA leads and supports the nation in a risk-based, comprehensive emergency management system of preparedness, response, recovery, assistance, and mitigation. In support of this mission, FEMA uses a wide variety of information systems and IT solutions and services. These systems, solutions, and services must be operated and maintained at the highest level of confidentiality, availability, and integrity.

OCS will provide oversight and management of the work and tasks orders under this Statement of Work. The mission of the FEMA OCIO is “to enhance and maintain IT infrastructure; develop and enhance key systems to support operating programs; increase efficiencies and cooperation across FEMA’s divisional and regional lines.” The vision and strategy of the OCIO is to modernize FEMA IT systems and services and to “deliver world-class secure IT guidance, products, and services to meet the needs of FEMA’s emergency managers and stakeholders nationwide.” The environment must be implemented with the flexibility required to support the evolving mission of FEMA and to support the surge requirements necessary to support emergency situations as they occur.

http://en.wiktionary.org/wiki/continental_United_States

Currently, FEMA’s IT environment is an amalgam of new and legacy technologies, architectures, platforms, and tools that includes a wide variety of PC-based, client-server, web-based and service-oriented components. The IT systems supporting FEMA’s mission has been implemented by using a variety of service providers under both mature and immature oversight and governance conditions. As stated above, the current goals are to continue the evolution and improvement of all IT services and support. The OCIO goal will be achieved by utilizing an approach and strategy that is consistent with both the Department and Agency strategy.

1.3 Objectives

The following are objectives of the FEMA Cyber Security Program:

• Perform gap analysis on current security infrastructure

• Ensure consistent application of information security standards across all agency information systems.

• Meet all regulatory and agency documented standards and guidance.

• Integrate these regulations and standards into a fully implementable security program.

• Ensure preparation for internal and external audits through management of all infrastructure artifacts required to pass audits.

• Ensure all new information technology (IT) projects meet or integrate security standards into their development.

• Develop a culture of security-mindful professionals across the community.

• Strive to be more flexible and responsive to new regulatory directives.

• Serve as the central authority for all Cyber Security-related activities across the agency.

• Ensure information system survivability and integrity.

• Optimize processes to meet Cyber Security-related goals and strategies

1.4 Applicable Documents

• National Institute of Standards and Technology (NIST), Special Publication (SP) 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems— A Security Life Cycle Approach, February 2010

• NIST SP 800-39, Managing Information Security Risk—Organization, Mission, and Information System View, March 2011

• NIST SP 500-53, Security and Privacy Controls for Federal Information Systems and Organizations

• NIST SP 500-53, Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans

• NIST SP 800-65, Integrating Cyber Security into the Capital Planning and Investment Control Process, dated January 2005

• 4300A Sensitive Systems Policy -- Version 11.0

• 4300A Sensitive Systems Policy Handbook -- Version 9.1 o Attachment B - Waivers Request Form -- Version 11 o Attachment C - ISSO Letter -- Version 11 o Attachment D - Type Accreditation -- Version 11 http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Policy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Handbook.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20B%5d%20Waiver%20Request%20Form.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20C%5d%20ISSO%20Letter.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20D%5d%20%20Type%20Accreditation.docx o Attachment E - FISMA Reporting -- Version11 o Attachment F - Incident Response -- Version 9.1 o Attachment G - Rules of Behavior -- Version 11 o Attachment H - POAM Process Guide -- UNDER REVISIONS -- Version 9.1 o Attachment I - Workstation Logon o Attachment K - IT Contingency Plan Template -- Version 11 o Attachment L - Password Management o Attachment M - 800-53 Controls -- Version11 o Attachment N - Interconnection Security Agreements -- Version 11 o Attachment O - Vulnerability Management -- Version 9.1 o Attachment P - Document Change Requests -- Version 11 o Attachment Q1 - Wireless Systems --Version 11 o Attachment Q2 - Mobile Devices -- Version 11 o Attachment Q3 - Tactical Systems o Attachment Q4 - RFID Systems -- Version 11 o Attachment R - Compliance Framework Guide -- Version 9.1 o Attachment S - Compliance Framework for Privacy Systems -- UNDER REVISIONS

-- Version 9.1 o Attachment S1 - Managing CREs containing SPII -- UNDER REVISIONS -- Version

9.1 o Attachment T - Acronyms o Attachment X - Social Media -- UNDER REVISIONS

• 4300B National Security System Policy Cover Page - Version 9.0

• 4300B National Security Systems Table of Contents - Version 9.0

• 4300B.100: Safeguarding and Risk Management for NSS

• 4300B.101 Risk Management for NSS

• 4300B.102 National Security System Security Control Guidance

• 4300B.103 Template Guidance o 4300B.103-1 Template for System Security Plans o 4300B.103-2 Template for Risk Assessment Reports o 4300B.103-3 Template for Security Assessment Reports o 4300B.103-4 Template for Plans of Action and Milestones

• 4300B.106 DHS NSS General and Privilege User Account Request Minimum Requirements

• 4300B.107 Decommissioning Strategy Minimum Requirements

• 4300B.108-1 National Security System References

• 4300B.108-2 National Security System Policy Change Request

• 4300B.200 Communication Security (COMSEC) - Version 2.0

• DHS Ongoing Authorization Methodology

• DHS CISO NIST SP 800-53 Security Controls tri-fold

• DHS FISMA System Inventory Methodology

• DHS Information Security Performance Plan http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20E%5d%20FISMA%20Reporting.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20F%5dIncident%20Response.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20G%5d%20%20Rules%20of%20Behavior.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20H%5dPOAM%20Guide.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20I%5dWorkstation%20Logon.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20K%5d%20%20IT%20Contingency%20Plan%20Template.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20L%5dPassword%20Management.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20M%5d%20Tailoring%20NIST%20800-53%20Security%20Ctrls.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20N%5d%20Interconnection%20Security%20Agreements.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20O%5dVulnerability%20Management.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20P%5d%20Document%20Change%20Requests.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q1%5d%20Sensitive%20Wireless%20Systems.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q2%5d%20Mobile%20Devices-CLEAN%20DRAFT.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q3%5dTactical%20Systems.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20Q4%5d%20Sensitive%20RFID%20Systems.docx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20R%5dCompli%20Fmwk%20CFO-designated%20Systems.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20S%5dCompliance%20Framework%20for%20Privacy%20Systems.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20S1%5dManaging%20CREs%20Containing%20SPII.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/%5b4300A%20HB%20Att%20T%5dAcronyms.doc http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.000%20National%20Security%20Systems%20Policy%20Coverpage.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.000_TOC_4300B_05102013.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.100%20-%20Safeguarding%20and%20Risk%20Mgmt%20for%20NSS.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.100%20-%20Safeguarding%20and%20Risk%20Mgmt%20for%20NSS.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.101%20-%20Risk%20Management%20Framework.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.101%20-%20Risk%20Management%20Framework.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.102%20-%20NSS%20Security%20Control%20Guidance%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.102%20-%20NSS%20Security%20Control%20Guidance%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-1%20-%20System%20Security%20Plans%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-1%20-%20System%20Security%20Plans%20FINAL.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103.2%20-%20Risk%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103.2%20-%20Risk%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-3%20-%20Security%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-3%20-%20Security%20Assessment%20Reports.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-4%20-%20Plans%20of%20Action%20and%20Milestones.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.103-4%20-%20Plans%20of%20Action%20and%20Milestones.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.106%20-%20User%20Minimum%20Requirements.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.107%20-%20Decommissioning%20Strategy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.107%20-%20Decommissioning%20Strategy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.108-1%20-%20NSS%20References.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.108.2%20-%20NSS%20Policy%20Change%20Request.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300B.200%20COMSEC.pdf

• DHS Security Authorization Process Guide

• DHS Document Review Methodology

• Document Review Checklists

• Security Authorization Document Templates

• FIPS-199 Workbook and Instructions

• Privacy Threshold Analysis (PTA) Template

2.0 SPECIFIC TASKS

2.1 Task 1 - Project Management

2.1.1 Background

A project is a temporary group activity designed to produce a unique product, service or result.

A tasks and activities executed within the OCS are treated as projects. Contractor shall provide project management services for OCS tasks and activities. Project Management services shall adhere to the PMI Project Management framework for project planning, scheduling, communications, reporting, and contractual activity and to ensure that any technical issues are addressed quickly and professionally.

2.1.2 Clearance Requirement

All personnel supporting this task must have a SECRET clearance and adhere to guidance outline within Section 10.0 of this document.

2.1.3 Mission/Objectives/Goals

The Offeror’s Project Manager shall be responsible for the Project Planning and Project Management aspects of this task. This task continues for the entire duration of the project.

This task includes the regularly scheduled meetings and specified documentation; i.e., Weekly Status Meeting, Weekly Status Reports, Weekly Work, Plan Review, Schedule Review, and Oversight/Stakeholder Reporting.

The Offeror shall develop a Program Management Plan (PMP) for the successful execution of the tasks within this SOW. The PMP shall include, as a minimum:

• Statement of Objectives (SOO)

• Chart of organizational relationships, authority, and responsibilities

• Plan of Actions and Milestones (POA&M)

• Time-phased budget for cost control

• Project Risk Identification

• A requirements document

• A continuity of business plan detailing certification processes and practices to aid in the event of a change of contractors

Work products such as Weekly Activity Reports, Monthly Activity Reports, Program Status Reports, and meetings shall be included in the PMP.

The Offeror shall develop a Project Plan to manage, schedule, and track progress using Microsoft (MS) Project. The current progress information shall be provided to the Government through contractor management meetings, monthly activity reports, and MS Project files.

• Provide leadership, management, and administrative support for contractor work in support of Cyber Operations. Specific activities include but are not limited to the following:

• Provide overall management and oversight of contract staff and activities to ensure all work comply with applicable Department and OCIO policies and regulations; ensure contractor performance is timely and meets OCIO/CISO program goals and performance standards

• Provide overall technical leadership and oversight; recommend and oversee the implementation of proactive and leading edge technical and technological approaches and solutions to address emerging cyber security trends; report on an annual basis

• Provide administrative support for contract work activities to include support Cyber Operations; prepare memorandums and correspondence; perform filing, passing of clearances, meeting and conference coordination, and other office administration duties

• Provide and finalize the Program Management Plan within 20 business days of contract start date.

• Provide and finalize individual Task Management Plan that addresses at a minimum, performance schedule, milestones, deliverables, and approaches to problem resolution and communication and coordination with Government personnel within 20 business days of contract start

• Provide and finalize GFE Inventory Management Procedures within 20 business days of contract start

• Monitor and track program and task performance to ensure on time service delivery within established cost estimates

• Identify, recommend, and implement (upon Government approval) cost-saving measures

• Provide monthly Task Status Report for each task (to the designated Government Technical Monitor) by the 15th of each month, presenting:

o Activities and milestones completed and deliverables submitted for each task for the past month o Indication of potential schedule variance, mitigation strategies, and actions taken o Issues encountered and resolution applied o Issues unresolved and current status and actions o Milestones and activities planned for the next reporting period

• Provide monthly Program Status Report (to the Contracting Officer’s Representative) by the 15th of each month, incorporating the Task Status Reports and the following for the overall program:

o Total cost incurred in the past month and fiscal year-to-date o Indication of potential cost and/or schedule variance, mitigation strategies, and actions taken o Funding and expenditure status o Staffing status to include current staffing level (%); positions open/unfilled and number of days open/unfilled o Cost saving measures implementation status including activities and milestones completed and planned

• Conduct Program and individual Task Status Review monthly, as requested by the

Program Manager and/or COR, to provide opportunity for report clarification and issue resolution

• Prepare and conduct quarterly Program Performance Reviews (IAW Quality Assurance Surveillance Plan) to include identification of potential cost saving measures in each task area and related implementation plans and status

• Support acquisition of materials and services incidental to contractor work activities

The Offeror shall submit a written Monthly Activity and Program Status Reports, to include but not limited to:

• A summary of accomplishments for the month which includes ,

• Updated of the SOW Plan of Action and Milestones (POA&M) schedule (originally delivered as part of the PMP) including milestones achieved and schedule changes

• Funding expended and funding remaining

• A copy of deliverables submitted to the government for acceptance,

• Program risks identified and mitigation action taken and planned

• A narrative of management or technical problems,

• Suggestions and Recommendations, and

• A projected schedule for next month’s activities

The Offeror shall develop and submit the following management controls reports:

• Contract Management Meetings,

• Use of Automated Tools

• Quality Control (QC) and Quality Assurance (QA) Procedures

The Offeror shall provide consulting services for this task to the government.

2.1.3.1 Regular Contractor Management Meetings

The Offeror and FEMA shall hold regularly scheduled monthly Contractor Management Meetings. The meeting shall provide the government and the Offeror an opportunity to discuss current tasking, provide additional guidance to the technical task management of the contract, and give the Offeror an opportunity to ask questions pertinent to the successful completion of the task.

2.1.3.2 Quality Control and Quality Assurance Procedures

Quality of data is paramount importance to the FEMA. The Offeror plays a critical role in establishing and maintaining the quality of the program. The Offeror shall perform the following:

• Data Collection Quality Control (QC) – The Offeror shall develop and implement a written QC program for data collection to ensure compliance with DHS and FEMA processes and procedures.

• Data Quality Assurance (QA) – The Offeror shall support and participate in the DHS QA review program as defined by the requirements of Contractors QA Procedures. The Offeror shall provide propose corrective actions to the COR to address any minor deficiencies identified in the review within five working days of receiving the QA report.

If the Offeror receives an unacceptable QA rating, FEMA may suspend the Offeror’s activities, by written notice from the Contracting Officer (CO) until acceptable adjustments have been implemented and an acceptable QA is earned by the Offeror.

The Offeror shall report all activities during travel, in a format specified by the Contracting Officer’s Representative (COR).

2.2 Task 2 - 24x7 Security Operations Center (SOC) Services

The FEMA SOC primary objectives are to provide Tier 1 and limited Tier 2 capabilities for 24x7x365 surveillance, situational monitoring, and cyber defense services; to provide the ability to rapidly detect and identify malicious activity and to promptly subvert that activity; and to collect data and maintain metrics that demonstrate the impact of the Agency’s cyber defense approach, its cyber state and cyber security posture.

The FEMA SOC monitors FEMA information systems, applications, network and network access points, analyzes network traffic to identify emerging threats, detects and coordinates the response and recovery efforts for cyber-attacks against FEMA, and provides leadership with security situational awareness information regarding the overall security risk posture of the enterprise information assets. The FEMA SOC regularly works with the DHS SOC and maintains up to date point of contact information and component capabilities to leverage resources in the event of a cyber-incident.

The FEMA SOC also serves as the central reporting point for computer security incidents within the Department and is the primary conduit for reporting computer security incidents to the

DHS.

The Network Monitoring/IDS Sensor Network primarily consists of tools deployed and managed by the network contractor that includes a complete suite of products that support the DHS and FEMA Continuous Monitoring capability.

Additional duties/services:

• Provide support 24x7x365

• Monitor the FEMA SOC hotline, email inboxes, fax and the ticketing system

• Investigate, analyze, remediate, and report on security events and incidents

• Report incident information to the DHS established timelines

• Maintain daily shift/ incident logs

• Produce reports on FEMA SOC activities

• Participate in the DHS meetings

• Collaborate with DHS SOC

• Perform inter-agency liaison; coordinate events/incidents information with operational managers and law enforcement entities within the Department, and with outside agencies

• Render technical assistance for criminal investigations and non-security related operational events

• Contribute input to the OCIO OCS Daily

• Provide monthly project status report as part of the Task Status Report by the 15th of each month

• Report on quality performance measures quarterly as part of the overall Program performance measures review

• The FEMA SOC produces several reports with the daily FEMA SOC Cyber Security Brief and the FEMA SOC Monthly Report being the key reports; see Table 1 for list of the key/major reports.

Report Description Publication Schedule

Cyber Security Briefing (CSB)

Highlights unclassified cyber security news, FEMA SOC/ cases opened and closed since the last reporting period, security updates from network operations, the firewall team, virus incident response team, and patch management.

7:00 a.m., Monday through Friday

Classified Cyber Security Briefing

(CCSB)

Highlights classified cyber security news, FEMA SOC cases opened and closed since the last reporting period, security updates from network operations, the firewall team, virus incident response team, and patch

As required and scheduled

Daily Status Update on Significant Cases

Provides updates on the development and resolution of security cases identified by the Government to have significant impact to

4:00 p.m., Monday through Friday

SPOT Report Provides notification to Key OCIO Leaderships of Critical Incidents; it is created and distributed at the direction of the Chief, Cyber Security.

Within 30 minutes upon Government approval

Daily Shift/Incident Log

Records all details related to an incident Continuously throughout the shift

FEMA SOC/CIRC

Monthly Report

Contains information such as:

• Number of new cases and closed cases

• Number of events and incidents

• Breakdown of cases by reporting groups (IDS, ISSO, Firewall, Other) and IDS event types

• E-mail traffic

• Listserv announcements – number sent and description of information relayed

• Number of external source events

• Number of cases referred to other

Federal agencies

• Detailed descriptions of significant events and incidents

• Other highlights, such as meetings and training attended and special reports

15th of each month

2.2.1 Background

The objectives of the Security Operations Center (SOC) are to protect, detect, respond, and recover from Information Security (IS) threats to the Federal Emergency Management Agency.

SOC tasks include advising the FEMA of proper security measures, encouraging industry best security practices, managing telephone trouble calls, issuance of Information System Security (ISS) Alerts, Advisories, Bulletins and ISS related information messages, administration of the SOC secure web page, incident handling and response, intrusion detection and analysis support, forensics, and metrics reporting. The SOC’s goal of achieving Cyber Security is accomplished by implementing layered defense methodologies by performing vulnerability assessment, compliance verification, security patch and virus notification, intrusion detection, incident handling and assistance with cyber disaster recovery, agency-wide.

2.2.2 Clearance Requirement

All personnel supporting this task must have a TOP SECRET/SCI clearance and adhere to guidance outline within Section 10.0 of this document.

2.2.3 Mission/Objectives/Goals

The overall mission of the SOC is to protect the FEMA’s critical Information Systems (IS) infrastructure and operations from being negatively influenced, disrupted, or terminated through the exploitation of internal or external automated IS. The primary objective of the SOC is to enhance the security of the FEMA network infrastructure, mission support systems, and administrative systems. Its goals are to protect, prevent, detect, respond, and recover.

The Offeror shall assist the SOC Management and the FEMA in maintaining and maturing the current 24 hours a day, seven days a week, 365 days per year operations center to protect the FEMA IT infrastructure. The Offeror must support traditional SOC type activities. The Offeror must be able to support these activities during periods of Continuity of Operations exercises.

That is, if it becomes necessary to temporarily relocate to a selected alternate site for emergency or test scenarios, the Offeror must be able to support, and extend normal SOC operations to that remote location. The specific tasks necessary for this escalation of capabilities are outlined in the following tasks. Staff qualification minimum requirements are also addressed. It should be noted that all staff shall be required to hold a current minimum active security clearance of TS/SCI unless otherwise noted.

The Offeror shall provide consulting services for this task to the government.

2.2.3.1 SOC Operations Team

2.2.3.1.1 SOC Operations – Response Group

2.2.3.1.1.1 Duty Officer Support

The Offeror shall support the SOC Watch Officer (WO) by actively participating in a variety of ISS activities, including: monitoring of systems status, analysis of ISS reports, use of various antivirus, intrusion detection, forensics and vulnerability assessment tools, techniques and procedures, policy development, program analysis and review, hardware and software evaluation and analysis, process improvement, data management, and coordination and reporting of ISS-related incidents. The Offeror Duty Officer (DO) may also be required to participate in assembling, evaluating, installing, and maintaining various intrusion detection sensors and associated software applications. The DO shall provide investigation, review, recommendation, and documentation as necessary. Documents created will include, but are not limited to, daily reports, and routine notifications. At a minimum, the DO must possess a current TS/SCI clearance.

2.2.3.1.1.2 Forensics Strike Force Support

The Offeror shall prepare a detailed written technical report covering the methodology used during the forensics evaluation, the findings from the evaluations, and any recommendation for further action. The report shall be provided to the SOC Management not later than five working days after completion of the evaluation. Forensics support may be required on short-notice.

2.2.3.1.1.3 Digital Media Analysis

2.2.3.1.1.4 Incident Response

Travel for incidence response fly away kits

2.2.3.1.1.5 Cyber Intelligence

The position shall possess a current TS/SCI clearance. Past experience shall include both documented experience in the intelligence and computer specialist fields, preferably combining these into a background of several years of Department of Defense/National level TS/SCI cyber intelligence analysis.

This FEMA cyber intelligence analyst will require technical expertise in hacker/hacktivist group capabilities and intentions to conduct computer network exploitation (CNE) and computer network attack (CNA) against the US Critical Infrastructure as it specifically relates to FEMA systems and mission. In addition, the cyber intelligence analyst shall be required to identify potential threats based on FEMA utilized hardware and software. They shall be knowledgeable of current and evolving hacking tools and methodologies available to disrupt these systems.

2.2.3.1.2 SOC Operations - Detection Group

2.2.3.1.2.1 Monitoring Sensor Devices

The Offeror shall maintain a 24 X 7 monitoring capability at the SOC operations facility, reviewing all SOC assigned sensors and reporting written or oral findings to the SOC Watch Officer for further processing.

2.2.3.1.3 SOC Operations - Protection Group

2.2.3.1.3.1 Protection Team Support

The Offeror personnel team assigned to support this subtask shall have a mix of the following knowledge, skills, abilities, and experience:

• LAN/System/Network administrator,

• Windows, Linux, and Novell networks,

• TCP/IP (Network System Engineering),

• Anti-virus software application(s),

• Host Based Solutions

• Vulnerability scanning tool(s), and

• Microsoft SQL

• Maintain awareness on "special threats"

• Maintain INFOSEC and Intelligence peer group contacts

• Respond to "special threats"

• Perform unscheduled Vulnerability Assessments

• Perform analytical analysis on compromised (& potentially compromised) systems

• Perform penetration tests

• Splunk

• Nitro

• Centrify

• Scripting (Perl, Java, Python, Powershell, Shell_

In addition, knowledge, skills, abilities, and experience with the following software applications are preferred:

• RedSeal

• Foundstone: FoundScan

• Nessus

• Veracode

• Wireless

2.2.3.1.3.2 Red Team/Blue Team

The Offeror shall provide a written report that contains remedial recommendations and vulnerability findings not later than five working days after completion of the assessment. The Offeror shall provide a written report, not later than five days after completion of the assistance, describing the incident response actions taken to rectify any discrepancy found and bring the system into compliance with FEMA requirements. The reports shall be delivered to the SOC Management.

2.2.3.2 SOC SUPPORT TEAM

2.2.3.2.1 Sensor Maintenance Support

When requested by the SOC Management, the Offeror shall develop a written plan that details the nature of the upgrade (hardware, software, etc.). This plan shall be submitted to the Chang Control Board (CCB). Once vetted through the CCB, the plan will then be submitted to the SOC Management within five working after the request and prior to making any changes to existing hardware or software.

If determined by the SOC management to install new sensors the Offeror will do the following:

working with the SOC government lead, the Offeror shall submit a detailed sensor deployment plan for SOC Management and COR approval prior to departing on travel. The document shall present a comprehensive plan pertaining to the installation of a new sensor or a sensor upgrade, to include the nature of the new installation or upgrade (hardware, software, etc.), and any other pertinent information. Sensor deployment technical trip reports shall be submitted within five business days after completion of travel.

The Offeror shall review the status of all existing sensors on a regular basis to ensure sufficient collection of pertinent data. If the review indicates a deficiency in coverage, the Offeror shall develop a sensor discrepancy report addressing the problem and detailing the steps required to correct the deficiency. The final report shall be submitted to the SOC Watch Officer within five working days of the finding.

2.2.3.2.2 SOC Support - Advanced Technology Group

2.2.3.2.2.1 Security Event Information Management Tool

The Offeror shall provide SEIM Engineer support as part of the Advanced Technology Group with research, development, integration and administration duties as directed by the SOC Management.

2.2.3.2.3 Advanced Solutions Developer

The Offeror shall provide one Developer who specializes in scripting languages. This person shall have no less than three years of hands-on experience in or one of the following areas:

• Perl

• VB Scripting

• Java

• XML

• Windows & Linux environment familiarity

• Python

• PowerShell

• Shell Scripting

2.2.3.2.4 Continuous Monitoring and Risk Scoring

The goal of the Continuous Monitoring and Risk Scoring (CMRS) is to continuously gather and document metrics from available sources in order to provide a real time score as to the risk and attack surface of FEMA networks and systems. This real time risk score may then be used by decision makers to apply resources to bring the FEMA networks to a level of acceptable risk. In addition to architecture, engineering, and development efforts to bring together several different systems into a server-oriented architecture based upon cloud technologies, basic and applied research will be conducted on how to obtain a consolidated risk score and what risk scores equate to acceptable risk. The following existing systems shall be utilized and consolidated into the CMRS.

The Offeror personnel team assigned to support cyber input feed shall have a mix of the following knowledge, skills, abilities and experience:

• Microsoft Windows Security Bulletin checks

• Third party application Bulletin Checks

• NIST NVD Published Data Feeds (CPE,CVE,CCE,CVSS)

• Monitor Cyber Security alerts

• McAfee ePolicy Orchestrator (ePO) Host Agent

• Microsoft Active Directory

• Nessus Raw Scan Data

• Windows Configuration Checks using Security Technical Implementation Guides (STIGS) updated quarterly from DISA

• Patch Validation -RedHat Satellite Server API (e.g. Host/Hardware/Software

Inventory, Configuration, Packages, Errata)

• Patch Validation –Microsoft SCCM (e.g. Host/Hardware/Software Inventory, Configuration, Packages, Errata)

• 800,000 Pass/Fail results in initial collection

• Other automated scripts such as (Perl/PowerShell/Python) providing output in common formats such as CSV, XML and raw text.

• Perform Data Analytics to identify gaps:

o Data feed health o Toolset visibility o SOC visibility into the enterprise o Software versions o Configuration Management deviations/drift o Unauthorized Software/Hardware o Least Functionality o Unnecessary privileges, file permissions, o Process/Procedures o Compromises / In

• Establish/Maintain CMRS reporting/dashboards at the Executive, Program, System Boundary, Site Location, other levels as necessary.

• Software versions and configurations (is Secure Shell server version and configurations), excessive file permissions, unnecessary services, & poor security practices

2.3 Task 3 - System/Application Vulnerability and Penetration Testing Support (Internal and External)

2.3.1 Background

2.3.2 Clearance Requirement

All personnel supporting this task must have a TOP SECRET/SCI clearance and adhere to guidance outline within Section 10.0 of this document.

2.3.3 Mission/Operations/Goals

This optional task provides the ability to increase the Tier 1 and/or Tier 2 capability to meet changes and expansion to the mission requirements. Specifically, this task provides the ability to perform analyses and studies to implement or integrate new capabilities or enhance existing processes and procedures to meet emerging MIRD requirements or improve operational efficiency. Specific activities include but are not limited to the following:

• Evaluate, test, recommend, integrate, implement, and/or support new methods, techniques, technologies, and products to improve operational efficiency and/or enable enhanced capabilities for FEMA SOC/EDCIRC, IV&V and Vulnerability Management to include capabilities for performing web and database scanning and scanning of other IT assets, monitoring and trend analysis of attempted external attacks, and protection of Personal Identifiable Information (PII)

• Contribute technical expertise in the development and implementation of the modernized, state- of-the-art IT infrastructure, and implementation of enterprise-wide protection capabilities and safeguards

• Interact and coordinate security monitoring and network defense and protection activities with other organizations and Department entities to support compliance with new and emerging national security and homeland security requirements

• Provide monthly project status report as part of the MIRD Task Status Report by the 15th of each month, containing details as described in paragraph 7.2, Program Management and Administration

• Report on quality performance measures quarterly as part of the overall Program performance review

This task will have multiple incremental increases in capacity, above the baseline identified in previous tasks, allowing the Government the flexibility to meet the mission requirements.

If/when executed the period of performance will be from the date of the contract action to the end of the current base period of performance and then will be rolled into the following baseline option.

At least annually, conduct perimeter network vulnerability scans

• Analyze scan results and coordinate with Cyber Security Operations staff to assist in identifying mitigation strategies

• Conduct a minimum of one complete penetration test for all Department networks and outsourced capabilities

• Interface and coordinate with third party organizations performing penetration testing and vulnerability scanning for the Department

• Interface and coordinate with the OCIO information Assurances Services Directorate to establish targets for testing, test schedule, test goals, and rules of engagement supporting System Accreditation activities

• Plan and coordinate White Cell participation in support of each specific penetration test

• Work with Department Legal for clearance on attack plans and rules of engagement

• Perform penetration testing, complying with NIST SP 800-115; produce reports and conduct management briefings on test activities, scenarios, results and recommendations

• Stay abreast of current attack vectors and unique methods for exploitation of computer networks.

• Develop unique exploit code and attack vectors to conduct penetration tests

• Render expertise and guidance to other cyber security programs regarding intrusion methods

• Provide monthly project status report as part of the MIRD Task Status Report by the 15th of each month,

• Report on quality performance measures quarterly as part of the overall Program performance measures review

The Offeror shall provide consulting services for this task to the government.

2.4 Task 4 – Adhoc and Surge Requirements

2.4.1 Background

This is applicable to all of the Task Areas. Ad hoc and surge requirements, within the scope of the requirement, will most certainly arise during the life of this contract. These situations will require the Offeror to respond with very little notice. Since response to these emergencies will not allow time to identify additional personnel, the Offeror’s personnel performing on current tasks will be diverted to these emergency requirements. If these requirements become prolonged, the Offeror may be requested to backfill personnel for various tasks to replace the personnel that have been diverted. Any changes to the FFP tasks will be dealt with through the Changes Clause.

2.4.2 Clearance Requirement

All personnel supporting this task must have a SECRET clearance and adhere to guidance outline within Section 10.0 of this document.

2.4.3 Mission/Operations/Goals

The Offeror shall provide consulting services for this task to the government.

3.0 DELIVERABLES

This section list deliverables identified within Section 2.

The Offer shall deliverables electronically using Microsoft Office suite of tools (for example, MS WORD, MS EXCEL, MS POWERPOINT, MS PROJECT, or MS ACCESS format), unless otherwise specified by the COR. Electronic submission shall be made via email, unless otherwise agreed to by the COR.

SOW

TASK # DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

2.1. TASK 1 - PROJECT MANAGEMENT

2.1 Task 1 – Project Management Plan Contractor-

Determined Format Standard Distribution

2.1 Task 1 – Weekly Activity Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Monthly Activity Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Program Status Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Project Schedules Contractor-

Determined Format

Standard Distribution

2.1 Task 1 - GFE Inventory Management Procedures Contractor-

Determined Format

Standard Distribution

2.1 Task 1 - Program Performance Reviews Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Task POA&M Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Management Controls Reports Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Meeting Minutes Contractor-

Determined Format

Standard Distribution

2.1 Task 1 – Travel Reports Contractor-

Determined Format

Standard Distribution

Monthly Performance and Progress Report Standard Distribution NLT 10th of each reporting period.

Program management plan Standard Distribution NLT 15 calendar DACA and updates as requested by COR Quality Assurance Plan (QAP) Standard Distribution NLT 15 calendar DACA and updates as requested by COR Monthly Performance and Progress Report Standard Distribution NLT 10th of each reporting period.

SOW

TASK # DELIVERABLE TITLE FORMAT DISTRIBUTION FREQUENCY REMARKS

Program management plan Standard Distribution NLT 15 calendar DACA and updates as requested by COR

Quality Assurance Plan (QAP) Standard Distribution NLT 15 calendar DACA and updates as requested by COR

In-briefs and Out-briefs

2.2 Task 2 – 24x7 Security Operations Center Services

In-briefs and Out-briefs Cyber Security Briefing (CSB) Classified Cyber Security Briefing (CCSB) Daily Status Update on Significant Cases SPOT Report Daily Shift/Incident Log

2.3 Task 3 – System/Application Vulnerability and Penetration Testing Services Information System Security Plan / Update Standard Distribution

Final Program Plan developed within 120 calendar DACA, Update due by July 30

Vulnerability Testing and Scanning Report, Server configuration change report

Wireless security assessments LAN security assessments Weekly interim status reports In-briefs and Out-briefs

2.14 Task 14 – Adhoc and Surge Requirements

Formal evaluation of Technical Approval requests Process improvement recommendations In-briefs and Out-briefs

4.0 PLACE OF PERFORMANCE

4.1 Project Management

Primary work site:

FEMA Head Quarters Site National Capital Region Washington, DC

Alternate work site:

1. Mount Weather Emergency Operations Center

2. Alternate Security Operations Center site

3. Department of Homeland Security Operations Center

4. FEMA/DHS contracted datacenters

5. Other Government owned or leased site(s)

4.2 24x7 Security Operations Center Services For the Security Operations Center, work will primarily be performed at:

Federal Emergency Management Agency/DHS Mount Weather Emergency Operations Center 19844 Blue Ridge Mountain Road Mt. Weather, VA 20135-2006

Alternate work site:

1. FEMA Head Quarters Site

2. Alternate Security Operations Center site

3. Department of Homeland Security Operations Center

4. FEMA/DHS contracted datacenters

5. Other Government owned or leased site(s)

Travel to other FEMA facilities may be required. This includes travel to FEMA fixed facilities or Offeror managed facilities within CONUS/OCONUS locations.

4.3 System/Application Vulnerability and Penetration Testing Services Region IX - Oakland Headquarters Locations:

1111 Broadway, Oakland, Ca 94607-4052 75 North Fair Oaks Ave, Pasadena, CA 91103 1301 Clay St. Oakland, CA 94607 3720 Dudley Blvd, McClellan Park, CA 95652

Region VII - Kansas City Headquarters Locations:

9221 Ward Parkway, Suite 300, Kansas City, Mo 64114-3372

850 SW Chipman Rd, Suite 500, Lees Summit, MO 64063 2312 E Bannister Rd, Kansas City, MO 64131

Region V - Chicago Headquarters Locations:

536 S. Clark Street, Chicago, Il 60605 635 New Indian Trail Rd, Aurora, IL 60506

Region VI - Denton Regional Center, MERS, NPSC Locations:

Federal Regional Center 800 N. Loop 288 Denton, Texas 76209-3698 1500 Main, Baton Rouge, LA 70802 1 Seine Ct, New Orleans, LA…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .