USC-8_Pre-Proprosal_(Att_2).pdf
PDF 869 KB Posted
- Attached to
- Universal Service Contract-8 (USC-8) Federal contract opportunity
- Solicitation number
- HTC711-15-R-W002
About this file
pre-proposal meeting slides (att 2)
View the file
Other files for this federal contract opportunity
Show all 39
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Together, we deliver.
USTRANSCOM Cyber Defense Contract Language Update
USTRANSCOM/TCJ6‐OI Current as of 1 June 15
Mike Jenkins, C|CISO, CISSP‐ISSEP, ISSMP Chief Information Security Officer
Comm: 618‐220‐4254
UNCLASSIFIED
• Contract Language Major Provisions
• What’s New?
• Cyber Defense Resources
Agenda
Contract Language Major Provisions
• Handling and Protection of Non‐Public Information
• Incident Handling
– Reporting Requirements
– Incident Report Content
– Incident Report Submission
– Incident Response Coordination
– Information Sharing
– Confidentiality and Non‐Attribution Statement
– Law Enforcement/Counterintelligence
What’s New?
• Handling and Protection of Non‐Public Information
– Protect and use information properly
• Incident Handling
– Reporting requirements
• Initial report as soon as possible; follow on reporting within 72 hours
• Submitted to Defense Cyber Crime Center (DC3) (http://dibnet.dod.mil/)
– Removed reference to advanced persistent threats (APTs)
– Report content – aligned with DFARS structure
What’s New?
• Incident Handling Additions
– Response coordination for follow up actions
– Information sharing (non‐attributable)
– Confidentiality and Non‐Attribution Statement
– Law Enforcement/Counterintelligence support
• Security report requirements
– Types: Non‐Compliance or Report Required
– Uses NIST 800‐53 vice previous CIS 20 Security Controls
• Non‐Compliance
1) Assess your compliance based on NIST 800‐53
Controls
2) Provide report to the Contracting Officer if a control is not applicable, or an alternate means is used
• Report required
1) Assess your compliance based on NIST 800‐53
Controls
2) Provide a report to the Contracting Officer in the format specified in the solicitation
What’s New?
Assessing Compliance
• Same general procedures apply for either in‐house or outsourced IT
• No government prescribed method to accomplish assessments
• A general approach:
– Download NIST SP 800‐53a, assessment procedures
– Review the control(s) and assessment procedure
– Determine if you or your IT provider comply with this control, or have an equivalent capability, in your environment
• If Yes: no action is required
• If No: provide explanation to the Contracting Officer
Resource: NIST SP 800‐53A http://csrc.nist.gov/groups/SMA/fisma/assessment.html
ASSESSMENT PROCEDURE
AT‐2 SECURITY AWARENESS
AT‐2.1 ASSESSMENT OBJECTIVE:
Determine if: the organization provides basic security awareness training to all information system users (including managers, senior executives, and contractors) as part of initial training for new users and when required by system changes; the organization defines the frequency of refresher security awareness training; the organization provides refresher security awareness training in accordance with the organization‐defined frequency;
POTENTIAL ASSESSMENT METHODS AND OBJECTS:
Examine: [SELECT FROM: Security awareness and training policy; procedures addressing security awareness training implementation; appropriate codes of federal regulations; security awareness training curriculum;
security awareness training materials; security plan; training records;
other relevant documents or records].
Interview: [SELECT FROM: Organizational personnel comprising the general information system user community].
Resource: Assessment Example
• Requirements streamlined
• NIST SP 800‐53 controls used
• Reports required if security control is not met or for “Report Required” type
• Incident reporting to the DC3
Summary
Mike Jenkins, CISO
USTRANSCOM/TCJ6‐OI
James.M.Jenkins2.civ@mail.mil
(618) 220‐4254
Questions?
UNCLASSIFIED
UNCLASSIFIED
Access Control Audit &
Accountability Identification and
Authentication Media Protection System & Comm
Protection
AC-2 AU-2 IA-2 MP-4 SC-2
AC-3(4) AU-3 IA-4 MP-6 SC-4
AC-4 AU-6(1) IA-5(1) SC-7
AC-6 AU-7
Physical and Environmental
Protection SC-8(1) AC-7 AU-8 Incident Response PE-2 SC-13
AC-11(1) AU-9 IR-2 PE-3
AC-17(2) IR-4 PE-5 SC-15
AC-18(1)
Configuration Management IR-5 SC-28
AC-19 CM-2 IR-6
Program
Management
AC-20(1) CM-6 PM-10
System & Information
Integrity AC-20(2) CM-7 Maintenance SI-2
AC-22 CM-8 MA-4(6) Risk Assessment SI-3
MA-5 RA-5 SI-4
Awareness & Training
Contingency Planning MA-6
AT-2 CP-9
Minimum Security Controls
File details come from the government source that posted it. Updated .