Atch_3_-_Security_Controls_and_Template_Updated13Mar13.pdf

PDF 285 KB Posted

Attached to
Stevedoring and Related Terminal Services (S&RTS) Master Solicitation (CONUS) Federal contract opportunity
Solicitation number
HTC711-14-R-R003
Issued by
Department of Defense United States Transportation Command

About this file

Security Controls and Template

View the file

Other files for this federal contract opportunity

Other files attached to Stevedoring and Related Terminal Services (S&RTS) Master Solicitation (CONUS), newest first.
File Type Posted
Call_0001_Synopsis_of_Award.pdf PDF
CALL_0005_Cape_Canaveral _FL_Amendment_02.pdf PDF
QA_for_MOTCO__14.pdf PDF
Atch_2- 1_Pricing_Schedule_Revised_.xlsx XLSX spreadsheet
CALL__0006_Atch_6_-_Q A_Questions_1-3.pdf PDF
Atch_2_CALL_0002-02__Pricing_Schedule.xls XLS spreadsheet
Call_0002_Texas_Gulf_Beaumont_Amd_02.pdf PDF
Atch_2_CALL_0002-02__Pricing_Schedule.xls XLS spreadsheet
CALL_0007_MOTCO_Pre_proposal_Information.pdf PDF
Q A_for_Seattle_20.pdf PDF
Atch_2_-_CALL_0004_Schedule_of_Rates_(Amendment_0004-02).xlsx XLSX spreadsheet
Atch_7_CALL_0002-01_Q A.pdf PDF
Atch_6_CALL_0002-01_Pre-proposal_Conference_Agenda.doc DOC document
Atch_2_CALL_0002-01__Pricing_Schedule.xls XLS spreadsheet
Call_0003_Atch_4-1_WD_2005-2559_.pdf PDF
Atch_3-1_2008-2014_ILWU_LOCAL_75_Agreement.pdf PDF
Atch_3-4_2008-2014_PCWBFA.pdf PDF
Atch_4-2_WD_2005-2071_Port_Hueneme.pdf PDF
Atch_5_Call_0001-01_WD_North_Carolina.pdf PDF
Atch_7_CALL_0001-01_PreProposal_Agenda.doc DOC document
Call_0001-01_Mid-Atlantic.pdf PDF
Atch_1_CALL_0001-01_Revised_PWS.pdf PDF
Atch_5_CALL_0001-01_WD_2005-2473_Charleston.pdf PDF
Atch_5_CALL_0001-01_WD_Savannah.pdf PDF
CALL_0005_Atch_2_-_Schedule_of_Rates_(Amendment_0005-01).xlsx XLSX spreadsheet
CALL_0005_Atch_6_-_Questions_ _Answers.pdf PDF
CALL_0005_Cape_Amendment_01.pdf PDF
CALL_0005_Atch_1_-_PWS_(Amendment_0005-01).pdf PDF
CALL_0005_Atch_5_-_PreProposal_Agenda.pdf PDF
Atch_1_-_CALL_0004_PWS_(Amendment_0004-01).pdf PDF
Atch_7_-_CALL_0004_PreProposal_Agenda.pdf PDF
AMD_01_Final_Atch_1_-_FAR_Part_12_Instructions_to_Offerors_ _Evaluation_.pdf PDF
HTC711-14-R-R003 _Amd_01.pdf PDF
Call_003_Pacific_NW_Question_1-8.pdf PDF
CALL_0006_Atch_5_-_WD.pdf PDF
MOTSU_Master_Call.pdf PDF
MOTSU_Master_Call.pdf PDF
CALL_0004_Jacksonville _FL.pdf PDF
Atch_4__-_CALL_0004_GFE.pdf PDF
Atch_3_-_CALL_0004_CBA.pdf PDF
Atch_2_-_CALL_0004_Schedule_of_Rates.xlsx XLSX spreadsheet
Atch_1_CALL_0003_PWS_Pacific_Northwest_(Seattle).pdf PDF
CALL_0003_Pacific_Northwest_(Seattle).pdf PDF
Atch_1_CALL_0002_PWS.pdf PDF
Atch_3_GFE_Beaumont_Solicitation.pdf PDF
CALL_0002 _Texas_Gulf_(Beaumont).pdf PDF
Atch_3_CALL_0001_GFE.pdf PDF
Atch_4_CALL_0001_CBA_.PDF PDF
HTC711-14-R-R003.pdf PDF
Atch_2_SB_Subcontracting_Plan(Template).doc DOC document
Show all 50

Stevedoring and Related Terminal Services (S&RTS) Master Solicitation (CONUS) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Vendor Assessment Guidelines for Twenty Critical Security Controls for

Effective Cyber Defense: Consensus Audit Guidelines (CAG)

General. Organizations should compare all 20 control areas against their current status.

The 20 Critical Controls are:

1. Critical Control 1: Inventory of Authorized and Unauthorized Devices

2. Critical Control 2: Inventory of Authorized and Unauthorized Software

3. Critical Control 3: Secure Configurations for Hardware and Software on Mobile Devices, Laptops, Workstations, and Servers

4. Critical Control 4: Continuous Vulnerability Assessment and Remediation

5. Critical Control 5: Malware Defenses

6. Critical Control 6: Application Software Security

7. Critical Control 7: Wireless Device Control

8. Critical Control 8: Data Recovery Capability

9. Critical Control 9: Security Skills Assessment and Appropriate Training to Fill Gaps

10. Critical Control 10: Secure Configurations for Network Devices such as Firewalls, Routers, and

Switches

11. Critical Control 11: Limitation and Control of Network Ports, Protocols, and Services

12. Critical Control 12: Controlled Use of Administrative Privileges

13. Critical Control 13: Boundary Defense

14. Critical Control 14: Maintenance, Monitoring, and Analysis of Audit Logs

15. Critical Control 15: Controlled Access Based on the Need to Know

16. Critical Control 16: Account Monitoring and Control

17. Critical Control 17: Data Loss Prevention

18. Critical Control 18: Incident Response and Management

19. Critical Control 19: Secure Network Engineering

20. Critical Control 20: Penetration Tests and Red Team Exercises

The entire text of the 20 Critical Security Controls is available for reference at:

http://www.sans.org/critical-security-controls/

Procedures:

1. Review each control.

2. Determine what procedures and tools exist within your organization to meet this control.

3. Document the result of 1-2 using the suggested template provided.

4. Provide any additional information about your company’s cyber security posture.

http://www.sans.org/cag/control/1.php http://www.sans.org/cag/control/2.php http://www.sans.org/cag/control/3.php http://www.sans.org/cag/control/3.php http://www.sans.org/cag/control/4.php http://www.sans.org/cag/control/5.php http://www.sans.org/cag/control/6.php http://www.sans.org/cag/control/7.php http://www.sans.org/cag/control/8.php http://www.sans.org/cag/control/9.php http://www.sans.org/cag/control/10.php http://www.sans.org/cag/control/10.php http://www.sans.org/cag/control/11.php http://www.sans.org/cag/control/12.php http://www.sans.org/cag/control/13.php http://www.sans.org/cag/control/14.php http://www.sans.org/cag/control/15.php http://www.sans.org/cag/control/16.php http://www.sans.org/cag/control/17.php http://www.sans.org/cag/control/18.php http://www.sans.org/cag/control/19.php http://www.sans.org/cag/control/20.php http://www.sans.org/critical-security-controls/

Company (Name): Information Assurance Report

Executive Summary: (descriptive self-assessment of the company’s overall information security posture)

A. Assessment of Twenty Critical Security Controls for Effective Cyber Defense:

Consensus Audit Guidelines (CAG)

1. Control 1. Inventory of Authorized and Unauthorized Devices

a. Procedures and Tools supporting this control:

(List the procedures and tools used in your organization for this control)

b. Method to achieve control metric:

2. (Continue for remaining 19 controls).

If a particular control does not exist or is not used within your organization, please state this.

B. Assessment of Additional Security Measures for Effective Cyber Defense

1. Measure. (Title of additional measure/control)

a. Procedures and Tools supporting this measure/control:

(List the procedures and tools used in your organization)

b. Method to achieve measure/control metric:

2. (Continue for remaining measures/controls)

File details come from the government source that posted it. Updated .