PWS_App_M_-_Cybersecurity_Controls_and_Template.pdf
PDF 140 KB Posted
- Attached to
- Request for Information/Draft PWS for DoD Freight Transportation Services Federal contract opportunity
- Solicitation number
- HTC711-14-ZR09
About this file
PWS Appendix M - Cybersecurity Controls and Template
View the file
Other files for this federal contract opportunity
Show all 24
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Vendor Assessment Guidelines for Twenty Critical Security Controls for
Effective Cyber Defense: Consensus Audit Guidelines (CAG)
The 20 Critical Security Controls are available at http://www.sans.org/critical-security-controls/.
The Contractor shall:
1. Review each control,
2. Determine what procedures and tools exist within your organization to meet this control,
3. Document the result of 1-2 using the format provided below. If a particular control does not exist or is not used within your organization, please state so, and
4. Provide any additional information about your company’s cyber security posture.
Report Format:
Company (Name): Information Assurance Report
Executive Summary: (descriptive self-assessment of the company’s overall information security posture)
A. Assessment of Twenty Critical Security Controls for Effective Cyber Defense: Consensus
Audit Guidelines (CAG)
1. Control 1. Inventory of Authorized and Unauthorized Devices
a. Procedures and Tools supporting this control:
(List the procedures and tools used in your organization for this control)
b. Method to achieve control metric:
2. (Continue for remaining 19 controls).
B. Assessment of Additional Security Measures for Effective Cyber Defense
1. Measure. (Title of additional measure/control)
a. Procedures and Tools supporting this measure/control:
(List the procedures and tools used in your organization)
b. Method to achieve measure/control metric:
2. (Continue for remaining measures/controls) http://www.sans.org/critical-security-controls/
File details come from the government source that posted it. Updated .