Appendix_3_-_Information_Assurance.pdf
PDF 87 KB Posted
- Attached to
- Alaska Air Cargo and Passenger Service Federal contract opportunity
- Solicitation number
- HTC71113RC001
About this file
Appendix 3 - PWS - Information Assurance
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 17_Jun_13_Solicitation_QA_posted_to_FBO.pdf | ||
| 14_June_2013_Solicitation_QA_posted_to_FBO.pdf | ||
| 12_JUNE_2013_-_Solicitation_QA.pdf | ||
| 4._7_Jun_2013_-_Solicitation_QA_posted_to_FBO_.pdf | ||
| 6_Jun_2013_-_Solicitation_QA_posted_to_FBOs.pdf | ||
| Exhibit_1_Fuel_Burn_Rate_.xlsx | XLSX spreadsheet | |
| Solicitation-HTC711-13-R-C001-0001.pdf | ||
| HTC711-13-R-C001_Questions_ _Answers.pdf | ||
| Exhibit_1_Fuel_Burn_Rate_.xlsx | XLSX spreadsheet | |
| Appendix_4_-_Monthly_Fuel_Report.docx | DOCX document | |
| HTC711-13-R-C001-SF1449.pdf | ||
| Appendix_2_-_Alaska_Mileage_Chart.pdf | ||
| Attachment_3_-_Wage_Determinations.pdf | ||
| Attachment_2_-_Past_Perf_Questionnaire.docx | DOCX document | |
| Solicitation-HTC711-13-R-C001.pdf | ||
| Appendix_1_-Acronyms_and_Definitions.pdf | ||
| Attachment_1_-_Performance_Work_Statement.pdf | ||
| Alaska_Charter_Airlift_Services_-_DRAFT_PWS.pdf |
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Appendix 3‐Information Assurance & Cyber Security
SOLICITATION: HTC711‐13‐R‐C001
30 April 2013
VENDOR ASSESSMENT GUIDELINES FOR TWENTY CRITICAL SECURITY CONTROLS FOR
EFFECTIVE CYBER DEFENSE: CONSENSUS AUDIT GUIDELINES (CAG)
General: Organizations should compare all 20 control areas against their current status.
The 20 Critical Controls are:
1. Inventory of Authorized and Unauthorized Devices
2. Inventory of Authorized and Unauthorized Software
3. Secure Configurations for Hardware and Software on Mobile Devices, Laptops, Workstations, and Servers
4. Continuous Vulnerability Assessment and Remediation
5. Malware Defenses
6. Application Software Security
7. Wireless Device Control
8. Data Recovery Capability
9. Security Skills Assessment and Appropriate Training to Fill Gaps
10. Secure Configurations for Network Devices such as Firewalls, Routers, and Switches
11. Limitation and Control of Network Ports, Protocols, and Services
12. Controlled Use of Administrative Privileges
13. Boundary Defense
14. Maintenance, Monitoring, and Analysis of Audit Logs
15. Controlled Access Based on the Need to Know
16. Account Monitoring and Control
17. Data Loss Prevention
18. Incident Response and Management
19. Secure Network Engineering
20. Penetration Tests and Red Team Exercises
The entire text of the 20 Critical Security Controls is available for reference at:
http://www.sans.org/critical‐security‐controls/
Procedures:
1. Review each control.
2. Determine what procedures and tools exist within your organization to meet this control.
3. Document the result of 1‐20 using the suggested template provided.
4. Provide any additional information about your company’s cyber security posture.
Company (Name): Information Assurance Report Executive Summary: (descriptive self‐assessment of the company’s overall information security posture) A. Assessment of Twenty Critical Security Controls for Effective Cyber Defense:
Consensus Audit Guidelines (CAG)
Appendix 3‐Information Assurance & Cyber Security
SOLICITATION: HTC711‐13‐R‐C001
30 April 2013
1. Control 1. Inventory of Authorized and Unauthorized Devices
a. Procedures and Tools supporting this control:
(List the procedures and tools used in your organization for this control)
b. Method to achieve control metric:
2. (Continue for remaining 19 controls).
If a particular control does not exist or is not used within your organization, please state this.
B. Assessment of Additional Security Measures for Effective Cyber Defense
1. Measure. (Title of additional measure/control)
a. Procedures and Tools supporting this measure/control:
(List the procedures and tools used in your organization)
b. Method to achieve measure/control metric:
2. (Continue for remaining measures/controls)
File details come from the government source that posted it. Updated .