Appendix_6.10 _Vendor_Assessment_Guidelines_for_20_Critical_Security_Controls.pdf

PDF 41 KB Posted

Attached to
Total Delivery Services (TDS) Federal contract opportunity
Solicitation number
HTC711-14-R-C001
Issued by
Department of Defense United States Transportation Command

About this file

Appendix 6.10 Vendor Assessment Guidelines for 20 Critical Security Controls (4 Apr 14)

View the file

Other files for this federal contract opportunity

Other files attached to Total Delivery Services (TDS), newest first.
File Type Posted
JA_Less_Than_Planeload_Requirements_3_Oct_2013.pdf PDF
TDS_Questions_and_Answers _as_of_12_May_14.pdf PDF
Attachment_2 _CLIN_Matrix _Amend_0006 _7_May_14.xlsx XLSX spreadsheet
TDS_Questions_and_Answers _as_of_7_May_14.pdf PDF
Amendment_0006_to_TDS_Solicitation _7_May_14.pdf PDF
Attachment_2 _CLIN_Matrix _Amend_0002 _17_Apr_14.xlsx XLSX spreadsheet
Attachment_1 _TDS_PWS _Amend_0005 _2_May_14.pdf PDF
Appendix_6.10_Vendor_Assessment_Guidelines_for_20_Critical_Security_Controls _Amend_0001 _15_Apr_14.pdf PDF
Amendment_0002_to_TDS_Solicitation _17_Apr_14.pdf PDF
Appendix_6.3 _Detail_Report_Required_Data_Element_Fields.pdf PDF
Appendix_6.11 _Semi-Annual_Report_of_Sales_ _Revenue_Template _Amend_0004 _28_Apr_14.xlsx XLSX spreadsheet
Attachment_2 _CLIN_Matrix _4_Apr_14.xlsx XLSX spreadsheet
Appendix_6.11 _Semi-Annual_Report_of_Sales_ _Revenue_Template _Amend_0002 _17_Apr_14.xlsx XLSX spreadsheet
Amendment_0003_to_TDS_Solicitation _23_Apr_14.pdf PDF
Attachment_7 _Historical_Int'l_Shipper_Snapshot _Amend_0001 _15_Apr_14.xlsx XLSX spreadsheet
TDS_Pre-Proposal_Conference_slides _as_of_28_Apr_14.ppt PPT presentation
Appendix_6.9 _Foreign_Carrier_Information_Sheet.docx DOCX document
Amendment_0005_to_TDS_Solicitation _2_May_14.pdf PDF
Attachment_1 _TDS_PWS _Amend_0001 _15_Apr_14.pdf PDF
Appendix_6.8 _Safety_and_Audit_Oversight_Checklist.pdf PDF
Attachment_4 _Past_Perf_Questionnaire _TDS.docx DOCX document
Attachment_2 _CLIN_Matrix _Amend_0004 _28_Apr_14.xlsx XLSX spreadsheet
Appendix_6.6 _TDS_Theaters _Amend_0003 _23_Apr_14.pdf PDF
Appendix_6.6 _TDS_Theaters _Amend_0004 _28_Apr_14.pdf PDF
TDS_Questions_and_Answers _as_of_23Apr_14.pdf PDF
TDS_Questions_and_Answers _as_of_15_Apr_14.pdf PDF
Appendix_6.2 _High_Volume_Shipping_Locations.pdf PDF
Appendix_6.11 _Semi-Annual_Report_of_Sales_ _Revenue_Template _Amend_0003 _23_Apr_14.xlsx XLSX spreadsheet
Attachment_3 _Wage_Determinations _Amend_0005 _2_May_14.pdf PDF
TDS_Solicitation_Summary_of_Changes _4_Apr_14.pdf PDF
Attachment_5 _Historical_Domestic_Shipper_Snapshot.xlsx XLSX spreadsheet
Appendix_6.6 _TDS_Theaters _Amend_0001 _15_Apr_14.pdf PDF
Appendix_6.5 _IGC_Data_Feed_Requirements _Amend_0003.pdf PDF
Amendment_0001_to_TDS_Solicitation _15_Apr_14.pdf PDF
Appendix_6.6 _TDS_Theaters _Amend_0002 _17_Apr_14.pdf PDF
Appendix_6.1 _Definitions_and_Acronyms.pdf PDF
Appendix_6.7 _Allowable_Delays _Exception_Codes.pdf PDF
Attachment_3 _Wage_Determinations.pdf PDF
TDS_Final_Solicitation _4_Apr_14.pdf PDF
Amendment_0004_to_TDS_Solicitation _28_Apr_14.pdf PDF
Appendix_6.6 _TDS_Theaters.pdf PDF
Appendix_6.11 _Semi-Annual_Report_of_Sales_ _Revenue_Template.xlsx XLSX spreadsheet
Attachment_4 _Past_Perf_Questionnaire _TDS _Amend_0002 _17_Apr_14.docx DOCX document
TDS_Questions_and_Answers _as_of_28_Apr_14.pdf PDF
Attachment_6 _SB_Subcontracting_Plan_Template.doc DOC document
Attachment_1 _TDS_PWS _4_Apr_14.pdf PDF
Attachment_1 _TDS_PWS _Amend_0003 _23_Apr_14.pdf PDF
Attachment_2 _CLIN_Matrix _Amend_0001 _15_Apr_14.xlsx XLSX spreadsheet
TDS_Questions_and_Answers _as_of_29_Apr_14.pdf PDF
Attachment_2 _CLIN_Matrix _Amend_0004 _28_Apr_14.xlsx XLSX spreadsheet
Show all 50

Total Delivery Services (TDS) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Appendix 6.10

VENDOR ASSESSMENT GUIDELINES FOR TWENTY CRITICAL SECURITY CONTROLS FOR

EFFECTIVE CYBER DEFENSE: CONSENSUS AUDIT GUIDELINES (CAG)

General: Organizations should compare all 20 control areas against their current status.

The 20 Critical Controls are:

1. Inventory of Authorized and Unauthorized Devices

2. Inventory of Authorized and Unauthorized Software

3. Secure Configurations for Hardware and Software on Laptops, Workstations, and Servers

4. Secure Configurations for Network Devices such as Firewalls, Routers, and Switches

5. Boundary Defense

6. Maintenance, Monitoring, and Analysis of Security Audit Logs

7. Application Software Security

8. Controlled Use of Administrative Privileges

9. Controlled Access Based on the Need to Know

10. Continuous Vulnerability Assessment and Remediation

11. Account Monitoring and Control

12. Malware Defenses

13. Limitation and Control of Network Ports, Protocols, and Services

14. Wireless Device Control

15. Data Loss Prevention

16. Secure Network Engineering

17. Penetration Tests and Red Team Exercises

18. Incident Response Capability

19. Data Recovery Capability

20. Security Skills Assessment and Appropriate Training to Fill Gaps

The entire text of the 20 Critical Security Controls is available for reference at:

http://www.sans.org/critical-security-controls/

Procedures:

1. Review each control.

2. Determine what procedures and tools exist within your organization to meet this control.

3. Document the result of 1-2 using the suggested template provided.

4. Provide any additional information about your company’s cyber security posture.

Company (Name): Information Assurance Report

Executive Summary: (descriptive self-assessment of the company’s overall information security posture)

A. Assessment of Twenty Critical Security Controls for Effective Cyber Defense: Consensus Audit Guidelines

(CAG)

1. Control 1. Inventory of Authorized and Unauthorized Devices

a. Procedures and Tools supporting this control:

(List the procedures and tools used in your organization for this control)

b. Method to achieve control metric:

2. (Continue for remaining 19 controls).

If a particular control does not exist or is not used within your organization, please state this.

B. Assessment of Additional Security Measures for Effective Cyber Defense

1. Measure. (Title of additional measure/control)

a. Procedures and Tools supporting this measure/control:

(List the procedures and tools used in your organization)

b. Method to achieve measure/control metric:

2. (Continue for remaining measures/controls)

File details come from the government source that posted it. Updated .