Appendix_4_-_Information_Assurance_ _Cyber_Security.pdf

PDF 87 KB Posted

Attached to
Domestic Charter Airlift Services Federal contract opportunity
Solicitation number
HTC711-14-R-C003
Issued by
Department of Defense United States Transportation Command

About this file

Appendix 4- Information Assurance Cyber Security

View the file

Other files for this federal contract opportunity

Other files attached to Domestic Charter Airlift Services, newest first.
File Type Posted
Final_RFP_Questions_and_Answers.pdf PDF
Questions_and_Answers_from_Domestic_Charter_Airlift_Services_PreSolicitation_Conference.pdf PDF
Industry_Day_2013_(2).pptx PPTX presentation
Questions_and_Answers_to_DRAFT_RFP.pdf PDF
Attachment_4_-_Fuel_Purchase_Agreement.pdf PDF
Appendix_3A-Solicitation_and_Award_Procedures_for_Full_Plane_Domestic_Charter_Airlift-135.pdf PDF
Attachment_2_-_Distance_Breaks_Pricing_Matrix_(FAA_Part_135).xlsx XLSX spreadsheet
Attachment_1_-_Performance_Work_Statement.pdf PDF
Wage_Determination_1993-0200_Revised_12_Feb_14.pdf PDF
HTC711-14-R-C003.pdf PDF
Appendix_4_-_Information_Assurance_ _Cyber_Security.pdf PDF
Appendix_6-Maintenance_Survey_Checklist.pdf PDF
Attachment_2_-_Distance_Breaks_Pricing_Matrix(FAA_Part_121).xlsx XLSX spreadsheet
Appendix_1_-_Acronyms_and_Definitions.pdf PDF
Appendix_7-_Ops_Mail-out_Checklis_2_Oct_2012.pdf PDF
Attachment_6_-_Past_Perf_Questionnaire.pdf PDF
Appendix_9_-_Monthly_Fuel_Report.pdf PDF
Appendix_3-Solicitation_and_Award_Procedures_for_Full_Plane_Domestic_Charter_Airlift-121.pdf PDF
Appendix_2_-_Government_Publications.pdf PDF
Appendix_8-ADFA_Implementation.pdf PDF
HTC711-14-R-C003_Cover_Letter.pdf PDF
Appendix_5-_Amc_Form_207.pdf PDF
Attachment_3_-_WAWF_Routing_Sheet.pdf PDF
Wage_Determination_1996-0460 _18.pdf PDF
Request_for_Information.docx DOCX document
Appendix_7-_Ops_Mail-out_Checklis_2_Oct_2012.pdf PDF
Attachment_2_-_Distance_Breaks_Pricing_Matrix(FAA_Part_121).xlsx XLSX spreadsheet
Attachment_6_-_Past_Perf_Questionnaire.pdf PDF
Appendix_8-ADFA_Implementation.pdf PDF
Attachment_3_-_WAWF_Routing_Sheet.pdf PDF
Appendix_3A-Solicitation_and_Award_Procedures_for_Full_Plane_Domestic_Charter_Airlift-135.pdf PDF
Appendix_1_-_Acronyms_and_Definitions.pdf PDF
Appendix_3-Solicitation_and_Award_Procedures_for_Full_Plane_Domestic_Charter_Airlift-121.pdf PDF
Appendix_6-Maintenance_Survey_Checklist.pdf PDF
Wage_Determination_1996-0460 _18.pdf PDF
Attachment_1_-_Performance_Work_Statement.pdf PDF
Attachment_2_-_Distance_Breaks_Pricing_Matrix_(FAA_Part_135).xlsx XLSX spreadsheet
HTC711-14-R-C003.pdf PDF
Wage_Determination_1993-0200_Revised_12_Feb_14.pdf PDF
Appendix_2_-_Government_Publications.pdf PDF
Attachment_4_-_Fuel_Purchase_Agreement.pdf PDF
Appendix_5-_Amc_Form_207.pdf PDF
Synopsis_ver2.doc DOC document
Show all 43

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Appendix 4‐Information Assurance & Cyber Security

HTC711‐14‐R‐C003

VENDOR ASSESSMENT GUIDELINES FOR TWENTY CRITICAL SECURITY CONTROLS FOR

EFFECTIVE CYBER DEFENSE: CONSENSUS AUDIT GUIDELINES (CAG)

General: Organizations should compare all 20 control areas against their current status.

The 20 Critical Controls are:

1. Inventory of Authorized and Unauthorized Devices

2. Inventory of Authorized and Unauthorized Software

3. Secure Configurations for Hardware and Software on Mobile Devices, Laptops, Workstations, and Servers

4. Continuous Vulnerability Assessment and Remediation

5. Malware Defenses

6. Application Software Security

7. Wireless Device Control

8. Data Recovery Capability

9. Security Skills Assessment and Appropriate Training to Fill Gaps

10. Secure Configurations for Network Devices such as Firewalls, Routers, and Switches

11. Limitation and Control of Network Ports, Protocols, and Services

12. Controlled Use of Administrative Privileges

13. Boundary Defense

14. Maintenance, Monitoring, and Analysis of Audit Logs

15. Controlled Access Based on the Need to Know

16. Account Monitoring and Control

17. Data Loss Prevention

18. Incident Response and Management

19. Secure Network Engineering

20. Penetration Tests and Red Team Exercises

The entire text of the 20 Critical Security Controls is available for reference at:

http://www.sans.org/critical‐security‐controls/

Procedures:

1. Review each control.

2. Determine what procedures and tools exist within your organization to meet this control.

3. Document the result of 1‐20 using the suggested template provided.

4. Provide any additional information about your company’s cyber security posture.

Company (Name): Information Assurance Report Executive Summary: (descriptive self‐assessment of the company’s overall information security posture) A. Assessment of Twenty Critical Security Controls for Effective Cyber Defense:

Consensus Audit Guidelines (CAG)

Appendix 4 – Information Assurance & Cyber Security

HTC711-14-R-C002

1. Control 1. Inventory of Authorized and Unauthorized Devices

a. Procedures and Tools supporting this control:

(List the procedures and tools used in your organization for this control)

b. Method to achieve control metric:

2. (Continue for remaining 19 controls).

If a particular control does not exist or is not used within your organization, please state this.

B. Assessment of Additional Security Measures for Effective Cyber Defense

1. Measure. (Title of additional measure/control)

a. Procedures and Tools supporting this measure/control:

(List the procedures and tools used in your organization)

b. Method to achieve measure/control metric:

2. (Continue for remaining measures/controls)

File details come from the government source that posted it. Updated .