USC-8_Pre-Proprosal_(Att_2).pdf

PDF 869 KB Posted

Attached to
Universal Service Contract-8 (USC-8) Federal contract opportunity
Solicitation number
HTC711-15-R-W002
Issued by
Department of Defense United States Transportation Command

About this file

pre-proposal meeting slides (att 2)

View the file

Other files for this federal contract opportunity

Other files attached to Universal Service Contract-8 (USC-8), newest first.
File Type Posted
HTC711-15-R-W002-0008.pdf PDF
HTC711-15-R-W002-0007.pdf PDF
HTC711-15-R-W002-0006.pdf PDF
HTC711-15-R-W002_Amendment_5.pdf PDF
New_CLINs_posted_22_July_15.pdf PDF
Deleted_and_Added_CLINs_17_Jul_15_(posted_21_Jul_15).pdf PDF
Added_CLINs_13_Jul_15_(posted_13_Jul_15).pdf PDF
HTC711-15-R-W002-0004.pdf PDF
Added_CLINS_7_July_15_(posted_9_July_15).pdf PDF
new_CLINs_July_1.pdf PDF
HTC711-15-R-W002-0003.pdf PDF
Pre-Proposal_Meeting_Minutes.pdf PDF
USC-8_Pre-Proposal_(Att_1).pdf PDF
BAF_Baselines.xlsx XLSX spreadsheet
HTC711-15-R-W002-0002.pdf PDF
USC8_Q As_26_Jun_15.pdf PDF
USC8_RFP_Questions_(23_JUN_15).pdf PDF
HTC711-15-R-W002-0001.pdf PDF
USC-8_RFP_Q As_(26_May_15).pdf PDF
USC-8_RFP_Questions.xlsx XLSX spreadsheet
USC-8_Draft_RFP_Q As_(FBO_Posting-26May15).pdf PDF
USC-8_RFP_HTC711-15-R-W002_(13MAY15).pdf PDF
USC-8_Milestones_7MAY15.pdf PDF
USC-8_Milestones_28JAN15.xlsx XLSX spreadsheet
USC-8_Att_2_Operational_Reports_Dec_2014.pdf PDF
USC-8_Industry_Day__19_Feb_15_.pdf PDF
Draft_Readiness_Language.pdf PDF
USC-8_Exhibit_2_Additional_Clauses_DRAFT_Dec_14.pdf PDF
USC-8_Att_8_DLA_Prime_Vendor_DRAFT_Dec_14.pdf PDF
USC-8_PWS_Att_3_Rate_Rules_DRAFT_Dec_14.pdf PDF
USC-8_PWS_Att_5_Route_Info_DRAFT_Dec_2014.pdf PDF
USC-8_PWS_DRAFT_Dec_14.pdf PDF
FINAL_Industry_Day_Agenda_Feb_15x.pdf PDF
USC-8_RFP_DRAFT_Dec_14.pdf PDF
USC-8_Att_1_EDI_Reports_DRAFT_Dec_14.pdf PDF
USC-8_Att_7_EPAs_DRAFT_Dec_2014.pdf PDF
USC-8_PWS_Contingency_Annex_DRAFT_Dec_2014.pdf PDF
USC-8_Exhibit_4_Ordering_Procedure_DRAFT_Dec_14.pdf PDF
USC-8_Att_6_Invoicing_and_Payment_DRAFT_Nov_14.pdf PDF
Show all 39

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Together, we deliver.

USTRANSCOM Cyber Defense Contract Language Update

USTRANSCOM/TCJ6‐OI Current as of 1 June 15

Mike Jenkins, C|CISO, CISSP‐ISSEP, ISSMP Chief Information Security Officer

Comm: 618‐220‐4254

UNCLASSIFIED

• Contract Language Major Provisions

• What’s New?

• Cyber Defense Resources

Agenda

Contract Language Major Provisions

• Handling and Protection of Non‐Public Information

• Incident Handling

– Reporting Requirements

– Incident Report Content

– Incident Report Submission

– Incident Response Coordination

– Information Sharing

– Confidentiality and Non‐Attribution Statement

– Law Enforcement/Counterintelligence

What’s New?

• Handling and Protection of Non‐Public Information

– Protect and use information properly

• Incident Handling

– Reporting requirements

• Initial report as soon as possible; follow on reporting within 72 hours

• Submitted to Defense Cyber Crime Center (DC3) (http://dibnet.dod.mil/)

– Removed reference to advanced persistent threats (APTs)

– Report content – aligned with DFARS structure

What’s New?

• Incident Handling Additions

– Response coordination for follow up actions

– Information sharing (non‐attributable)

– Confidentiality and Non‐Attribution Statement

– Law Enforcement/Counterintelligence support

• Security report requirements

– Types: Non‐Compliance or Report Required

– Uses NIST 800‐53 vice previous CIS 20 Security Controls

• Non‐Compliance

1) Assess your compliance based on NIST 800‐53

Controls

2) Provide report to the Contracting Officer if a control is not applicable, or an alternate means is used

• Report required

1) Assess your compliance based on NIST 800‐53

Controls

2) Provide a report to the Contracting Officer in the format specified in the solicitation

What’s New?

Assessing Compliance

• Same general procedures apply for either in‐house or outsourced IT

• No government prescribed method to accomplish assessments

• A general approach:

– Download NIST SP 800‐53a, assessment procedures

– Review the control(s) and assessment procedure

– Determine if you or your IT provider comply with this control, or have an equivalent capability, in your environment

• If Yes: no action is required

• If No: provide explanation to the Contracting Officer

Resource: NIST SP 800‐53A http://csrc.nist.gov/groups/SMA/fisma/assessment.html

ASSESSMENT PROCEDURE

AT‐2 SECURITY AWARENESS

AT‐2.1 ASSESSMENT OBJECTIVE:

Determine if: the organization provides basic security awareness training to all information system users (including managers, senior executives, and contractors) as part of initial training for new users and when required by system changes; the organization defines the frequency of refresher security awareness training; the organization provides refresher security awareness training in accordance with the organization‐defined frequency;

POTENTIAL ASSESSMENT METHODS AND OBJECTS:

Examine: [SELECT FROM: Security awareness and training policy; procedures addressing security awareness training implementation; appropriate codes of federal regulations; security awareness training curriculum;

security awareness training materials; security plan; training records;

other relevant documents or records].

Interview: [SELECT FROM: Organizational personnel comprising the general information system user community].

Resource: Assessment Example

• Requirements streamlined

• NIST SP 800‐53 controls used

• Reports required if security control is not met or for “Report Required” type

• Incident reporting to the DC3

Summary

Mike Jenkins, CISO

USTRANSCOM/TCJ6‐OI

James.M.Jenkins2.civ@mail.mil

(618) 220‐4254

Questions?

UNCLASSIFIED

UNCLASSIFIED

Access Control Audit &

Accountability Identification and

Authentication Media Protection System & Comm

Protection

AC-2 AU-2 IA-2 MP-4 SC-2

AC-3(4) AU-3 IA-4 MP-6 SC-4

AC-4 AU-6(1) IA-5(1) SC-7

AC-6 AU-7

Physical and Environmental

Protection SC-8(1) AC-7 AU-8 Incident Response PE-2 SC-13

AC-11(1) AU-9 IR-2 PE-3

AC-17(2) IR-4 PE-5 SC-15

AC-18(1)

Configuration Management IR-5 SC-28

AC-19 CM-2 IR-6

Program

Management

AC-20(1) CM-6 PM-10

System & Information

Integrity AC-20(2) CM-7 Maintenance SI-2

AC-22 CM-8 MA-4(6) Risk Assessment SI-3

MA-5 RA-5 SI-4

Awareness & Training

Contingency Planning MA-6

AT-2 CP-9

Minimum Security Controls

File details come from the government source that posted it. Updated .