Cyber_Security_Guidelines_and_Lessons_Learned.pdf

PDF 101 KB Posted

Attached to
USTRANSCOM VISA Contingency Contract Federal contract opportunity
Solicitation number
HTC711-15-R-WV01
Issued by
Department of Defense United States Transportation Command

View the file

Other files for this federal contract opportunity

Other files attached to USTRANSCOM VISA Contingency Contract, newest first.
File Type Posted
9. Atch 7 - NIST.SP.800-171_POAM_Template 2023.pdf PDF
2023.06.12_Updated VISA Terms and Conditions (REV 2).pdf PDF
9. Atch 7 - NIST.SP.800-171_POAM_Template 2022 V1.pdf PDF
Amendment 5 Released.pdf PDF
Atch 10 - Federal Register 2019 - 5 Year Extension.pdf PDF
Solicitation Amendment 4.pdf PDF
Atch 7 - NIST.SP.800-171_POAM_Template New for 2021 V5.pdf PDF
Atch 7 - NIST.SP.800-171 - POAM (w 3.12.4).xlsx XLSX spreadsheet
Amendment 0003.pdf PDF
Atch 9 - Federal Register 2018.pdf PDF
Atch 8 - Federal Register 2014.pdf PDF
Exhibit 1 BAF updated 24 June 2019.pdf PDF
Atch 2 - VISA Carrier Vessel Information Sheet.pdf PDF
Amendment_0002.pdf PDF
Atch._7_-_NIST.SP.800-171_-_POAM_-_Template.xlsx XLSX spreadsheet
Atch._8_-_Federal_Register-_2018.pdf PDF
Atch_4_-_Liner_T_ _Cs_(Amd_1-_Tracked_Changes).pdf PDF
SF1449_Exhibit_1_-_Bunker_Adjustment_Factor_(BAF).pdf PDF
HTC711-15-R-WV01_-_VISA_Solicitation_(Amd_1_Tracked_Changes).pdf PDF
HTC711-15-R-WV01-0001.pdf PDF
VISA_Q A's.pdf PDF
HTC711-15-R-WV01_-_VISA_Solicitation_(All).pdf PDF
Atch_4_-_Liner_Terms_ _Conditions_(Final).pdf PDF
HTC711-15-R-WV01_-_VISA_Solicitation_(SF1449).pdf PDF
Atch_6_-_VISA_DD254_(Final).pdf PDF
Atch_1_-_VISA_Capacity_Commitment.pdf PDF
Atch_3_-_Charter_Terms_and_Conditions_(Final).pdf PDF
Atch_7_-_Minimum_Security_Controls.pdf PDF
Atch_5_-_VISA_Rate_Methodologies_A_ _B_Guidance_(Final).pdf PDF
Atch_2_-_VISA_Carrier_Vessel_Information_Sheet.pdf PDF
Atch_8_-_2014_VISA_Fed_Register_Notice_10-29-2014.pdf PDF
VISA_Industry_Day_Agenda.pptx PPTX presentation
Draft_VISA_Solicitation_-_SF1449_-_All_Attachments_(Clean).pdf PDF
VISA_Industry_Day_12-10-14_Minutes.pdf PDF
VISA_Industry_Day_Agenda_ _Discussion_Slides.pdf PDF
VISA_Industry_Day_Agenda.pdf PDF
Map_for_VISA_Industry_Day.pptx PPTX presentation
VISA_DRAFT_Solicitation.pdf PDF
VISA_Draft_Charter_T Cs.pdf PDF
2014_VISA_Fed_Register_Notice.pdf PDF
VISA_Carrier_Vessel_Information_Sheet.pdf PDF
VISA_Capacity_Commitment_-_Attachment_I.pdf PDF
Draft_VISA_DD254.pdf PDF
Draft_VISA_Business_Rules.pdf PDF
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Vendor Assessment Guidelines for Twenty Critical Security Controls for Effective Cyber Defense: Consensus Audit Guidelines (CAG)

General. Organizations should compare all 20 control areas against their current status.

The 20 Critical Controls are:

1. Critical Control 1: Inventory of Authorized and Unauthorized Devices

2. Critical Control 2: Inventory of Authorized and Unauthorized Software

3. Critical Control 3: Secure Configurations for Hardware and Software on Mobile Devices, Laptops, Workstations, and Servers

4. Critical Control 4: Continuous Vulnerability Assessment and Remediation

5. Critical Control 5: Malware Defenses

6. Critical Control 6: Application Software Security

7. Critical Control 7: Wireless Device Control

8. Critical Control 8: Data Recovery Capability

9. Critical Control 9: Security Skills Assessment and Appropriate Training to Fill Gaps

10. Critical Control 10: Secure Configurations for Network Devices such as Firewalls, Routers, and

Switches

11. Critical Control 11: Limitation and Control of Network Ports, Protocols, and Services

12. Critical Control 12: Controlled Use of Administrative Privileges

13. Critical Control 13: Boundary Defense

14. Critical Control 14: Maintenance, Monitoring, and Analysis of Audit Logs

15. Critical Control 15: Controlled Access Based on the Need to Know

16. Critical Control 16: Account Monitoring and Control

17. Critical Control 17: Data Loss Prevention

18. Critical Control 18: Incident Response and Management

19. Critical Control 19: Secure Network Engineering

20. Critical Control 20: Penetration Tests and Red Team Exercises

The entire text of the 20 Critical Security Controls is available for reference at:

http://www.sans.org/critical-security-controls/

Procedures:

1. Review each control.

2. Determine what procedures and tools exist within your organization to meet this control.

3. Document the result of 1-2 using the suggested template provided.

4. Provide any additional information about your company’s cyber security posture.

Company (Name): Information Assurance Report

Executive Summary: (descriptive self-assessment of the company’s overall information security posture)

A. Assessment of Twenty Critical Security Controls for Effective Cyber Defense:

Consensus Audit Guidelines (CAG)

1. Control 1. Inventory of Authorized and Unauthorized Devices

a. Procedures and Tools supporting this control:

(List the procedures and tools used in your organization for this control)

b. Method to achieve control metric:

2. (Continue for remaining 19 controls).

If a particular control does not exist or is not used within your organization, please state this.

B. Assessment of Additional Security Measures for Effective Cyber Defense

1. Measure. (Title of additional measure/control)

a. Procedures and Tools supporting this measure/control:

(List the procedures and tools used in your organization)

b. Method to achieve measure/control metric:

2. (Continue for remaining measures/controls)

LESSONS LEARNED/SUBMISSION RECOMMENDATIONS

RELATED TO USTRANSCOM CYBER DEFENSE CONTRACT LANGUAGE

FOR NON‐INFORMATION TECHNOLOGY (IT) REQUIREMENTS

Cyber defense contract language for non‐IT requirements

• Submission with proposal:

– Assess your security program based on SANS 20 Critical Security Controls for Cyber Defense (http://www.sans.org/critical‐security‐controls). The latest version is available at this link and descriptions for each control are detailed, along with a description of each control, how to implement the control, procedures and tools for the control, and effectiveness metrics and test examples

– Submit a security plan addressing SANS 20 Critical Security Controls and describing how your environment safeguards DOD information resident on or transiting unclassified information systems from unauthorized access and disclosure.

• After contract award:

– Implement the security plan you submitted with your proposal

– Report incidents in accordance with contract requirements and comply with other aspects in the contract, including reporting of incidents to the USTRANSCOM Cyber Operations Center (CyOC)

General observations in reviewing cyber defense proposal submissions

• Responses not in format specified in solicitation

– Example: the template requires responses to the 20 Critical Security Controls to have two parts for each of the 20 controls:

a. Procedures and tools supporting this control: (List the procedures and tools used in your organization for this control)

b. Method to achieve control metric: (what metrics are in place to measure the effectiveness of the control) A frequent problem is receiving submissions that do not have both Procedures and Tools, and Method to Achieve control Metric. Both are required.

• Responses provided do not address intent of the control

• Responses lack sufficient detail to determine if intent of the control is met

• Response is missing or incomplete for a control

Specific observations in reviewing cyber defense proposal submissions

• Control responses with high percentage of problems:

– A significant number of responses for SANS Control 6 (Application Software Security) responses frequently do not address intent of control

– Responses should consider the description of the control, and measures described for how to implement the control, found at: http://www.sans.org/critical‐security‐ controls/control/6

Frequently Asked Questions:

1. How are contractors’ Information Assurance Reports evaluated?

Answer: Contractor’s responses/assessments to the SANS 20 Critical Controls “Procedures and Tools” and “Methods” are reviewed and rated either ACCEPTABLE or UNACCEPTABLE by Government personnel.

2. How is cyber security requirements monitored?

Answer: The contracting officer may request an updated Information Assurance Report 30 days prior to the exercise of an option period.

File details come from the government source that posted it. Updated .