J-8 AFDM Cybersecurity 18Jun2021.docx

DOCX document 79 KB Posted

Attached to
Auxiliary Floating Dry Dock Medium (AFDM) Draft RFP Federal contract opportunity
Solicitation number
N00024_21_R_2243
Issued by
Department of the Navy Naval Sea Systems Command

About this file

This document contains cybersecurity requirements for control and communications systems for an Auxiliary Floating Dry Dock, Medium (AFDM). The contractor must apply cybersecurity measures to all information technology associated with control systems, including configuring systems according to Security Technical Implementation Guides, mitigating all identified vulnerabilities, and documenting systems. The contractor must also implement firewalls, intrusion detection and prevention systems, remove unnecessary services and programs, enforce identification and authentication requirements, and monitor for unauthorized activities. Audit records must be generated for various security events and retained for at least one year.

View the file

Other files for this federal contract opportunity

Other files attached to Auxiliary Floating Dry Dock Medium (AFDM) Draft RFP, newest first.
File Type Posted
Addendum L-5 ID of Commercial Data.doc DOC document
Addendum L-3 Commercial Warranty Terms.docx DOCX document
Attachment J-7 AFDM IDE.docx DOCX document
J-4 Item Unique Identification.docx DOCX document
Attachment J-2 AFDM DRL 06 AUG 2021.docx DOCX document
DRAFT AFDM N00024-21-R-2243 082021.docx DOCX document
Addendum L-7 Past Performance Form.doc DOC document
Addendum L-4 ID of Non Commercial Data.doc DOC document
Addendum L-9 Certifications Regarding Responsibility Matters.doc DOC document
Addendum L-8 Pricing Summary.xlsx XLSX spreadsheet
Addendum L-6 Proposed Delivery Schedule Form.xls XLS spreadsheet
Attachment J-1 AFDM PSPEC 05 AUG 2021.docx DOCX document
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

N00024-17-R-2207 Attachment J-9 CYBERSECURITY REQUIREMENTS FOR CONTROL AND COMMUNICATIONS SYSTEMS

AUXILIARY FLOATING DRY DOCK, MEDIUM (AFDM)

CYBERSECURITY REQUIREMENTS FOR CONTROL AND COMMUNICATIONS SYSTEMS FOR SERVICE CRAFT Attachment J-8

XX Month 2021

Prepared by Naval Sea Systems Command 1333 Isaac Hull Ave. SE Washington Navy Yard, DC 20376-2101

DEPARTMENT OF THE NAVY PROGRAM EXECUTIVE OFFICE, SHIPS WASHINGTON, DC 20376

1. GENERAL

The Contractor shall apply cybersecurity measures to all Contractor-furnished information technology associated with control systems. For purposes of this contract, the following definitions are provided:

a.) Information Technology (IT) is defined as any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information.

b.) Operational Technology (OT) Devices, sensors, software and associated networking that monitor and control onboard systems; specifically for AFDM, control systems include all hardware and software included in machinery control systems, bridge and navigational systems, and exterior communication systems.

In addition to the requirements specifically called out, the Contractor should be aware that general cybersecurity and cybersecurity practices call for a comprehensive risk based approach that relies on adherence to 5 the NIST Risk Management Framework as defined by NIST’s Special Publications range and FIPS requirements. Cybersecurity/cybersafety practices should be consistent with industry-standard best practices and not depend solely on the requirements identified herein.

The Contractor shall ensure that development of all control and communications systems adhere to software secure coding best practices, and that control systems are configured in accordance with applicable Security Technical Implementation Guides (STIGs) published by the Defense Information Systems Agency.

Prior to delivery and acceptance, the Contractor shall mitigate all identified and validated cybersecurity/cybersafety vulnerabilities in IT and OT systems. Ongoing identification of such vulnerabilities is a Contractor responsibility up to delivery, with the Government also exercising the option to conduct independent vulnerability analysis as required. In cases where mitigation of vulnerabilities is not possible, the Contractor will provide an explanation in writing and documentation so that any residual risk can be evaluated by the Government. The Government shall be the sole arbiter for identification and resolution acceptance of cybersecurity issues/vulnerabilities.

The Contractor shall identify and document any detrimental impacts to ship systems’ performance (e.g., timing, performance, availability, etc.) From cybersecurity/cybersafety controls that do not allow the product to conform to engineering requirements stated elsewhere in the specification/contract. The Government will adjudicate these concerns.

The Contractor shall recommend spare parts lists for IT and OT systems, as part of the Vendor- Recommended Spares listing, to support the ability to maintain and repair the systems within 24 hours of a failure.

In selecting IT and OT devices other than those specified in J-1 and J-6, the contractor shall default to selection of National Information Assurance Partnership (NIAP) approved products (e.g. servers, operating systems, routers, firewalls). When NIAP products are available, but not selected, the Contractor shall provide its decision rationale to the Government prior to a purchase decision.

2. DOCUMENTATION

The Contractor shall ensure that all IT/OT systems are documented in accordance with DI 021-24 and DI-061 requirements. A full inventory of all IT/OT equipment will be maintained during the project (subject to inspection or request) and be made part of the baseline documentation provided to the Government at delivery.

The Contractor shall document control and communication systems as follows:

a) Provide a mapping of:

1. Software to hostname

2. Hostname to Internet Protocol address(es)

3. Internet Protocol address(es)(with subnet mask)(or non-IP address) to functional area/enclave

4. functional area/enclave to Virtual Local Area Network (VLAN)

5. Virtual Local Area Network (VLAN) to hardware

6. Hardware to location aboard the service craft.

b) Diagram of all networked systems - show hardware, hostname, IP addresses, type of connection (such as, TCP/IP via cable/fiber, RS-232)

c) Purpose or function of each piece of hardware, software, and hostname (in the case of virtual servers)

d) Ports, protocols, and services used to communicate between components

e) Configurations of firewalls, routers, switches, and other network-related equipment

3. REMOVAL OF UNNECESSARY SERVICES AND PROGRAMS

The Contractor shall install or enable, as applicable, only those applications, ports, protocols, services, and functions necessary for designed capabilities of a given control system. Control systems shall use enforcement mechanisms (such as, application whitelisting or equivalent technology) to prevent unauthorized software from executing on the systems.

The Contractor shall provide a listing of services required for any computer system running control system applications or required to interface the control system applications. The listing shall include all ports and services required for normal operation as well as any other ports and services required for emergency operation. The listing shall also include an explanation or cross reference to justify why each service is necessary for operation.

The Contractor shall verify and provide documentation that all services are patched to current status. The Contractor shall provide appropriate software and service updates and/or workarounds to mitigate all vulnerabilities associated with the product and to maintain the established level of system security.

The Contractor shall remove and/or disable all software components that are not required for the operation and maintenance of the control system prior to Factory Acceptance Testing. The Contractor shall provide documentation on what is removed and/or disabled.

4. HOST INTRUSION DETECTION SYSTEM

The Contractor shall provide a configured host intrusion detection system (HIDS) and/or provide the information to configure a HIDS to include, but not be limited to, static file names, dynamic file name patterns, system and user accounts, execution of unauthorized code, host utilization, and process permissions sufficient for configuring the HIDS.

The Contractor shall configure the HIDS such that all system and user account connections are logged. This log will be configured such that an alarm can be displayed to the operator if an abnormal situation occurs.

The Contractor shall recommend a configuration for the HIDS in a manner that does not negatively impact the operating system function.

5. INTRUSION PROTECTION SYSTEM

The Contractor shall employ McAfee Host Intrusion Prevention System protection where it is compatible with the information system. If the system is not compatible with the McAfee Host Intrusion Prevention System, the Contractor shall employ malicious code protection mechanisms at control system entry and exit points to detect and eradicate malicious code.

Means shall be provided to update the malicious code protection mechanisms to identify the latest malicious code. The Contractor shall configure malicious code protection mechanisms to perform real-time scans of files from external sources at control system entry/exit points as the files are downloaded, opened, or executed; and prevent confirmed additions of executables/binaries from executing without interfering with real-time operation of the control systems. The malicious code protection mechanisms shall prevent the download and execution of Mobile Code from outside the control systems boundary.

6. SYSTEM AND INFORMATION INTEGRITY

The control systems shall monitor inbound and outbound communications traffic for unauthorized activities or conditions. Monitoring shall be done at the entry/exit points and selected points at the intra-system network taps. The control systems shall employ integrity verification tools to detect unauthorized changes to the software, firmware and run-time behavior. The controls systems shall provide alerts when compromise or potential compromise occurs that changes the certified/qualified baseline configuration, to include software, hardware, firmware and run-time behavior. When compromise or potential compromise is detected, the control system shall be configured to disable network access by the component and notify the Administrator.

If the control systems employ a network, the network shall implement the DoD’s Host Based Security System (HBSS), if compatible.

7. CHANGES TO FILE SYSTEM AND OPERATING SYSTEM PERMISSIONS

The Contractor shall configure hosts with “least privilege” file and account access and provide documentation of the configuration. The Contractor shall configure the necessary system services to execute at the least user privilege level possible for that service and provide documentation of the configuration.

The control systems shall enforce access restrictions and support auditing of the enforcement actions. The control systems shall prevent the installation of unauthorized software using detection/enforcement mechanisms (for example, hash authentication or equivalent technology) and validate authorized software being installed on the system.

The control systems shall provide alerts when the unauthorized installation of software is detected. The control systems shall prohibit user installation of software without explicit privileged status.

8. HARDWARE CONFIGURATION

The Contractor shall disable, through software or physical disconnection, all unneeded communication ports and removable media drives, or provide engineered barriers, and provide documentation of the results. The Contractor shall password protect the BIOS from unauthorized changes unless it is not technically feasible, in which case the Contractor shall document this case and provide mitigation measures.

The Contractor shall configure the network devices to limit access to/from specific locations, where appropriate, and provide documentation of the configuration. The Contractor shall configure the system to allow the system administrators the ability to re-enable devices if the devices are disabled by software and provide documentation of the configuration.

9. INSTALLING OPERATING SYSTEMS, APPLICATIONS, AND THIRD-PARTY SOFTWARE UPDATES

The Contractor shall have a patch management and update process. The Contractor shall remove previous versions of software and firmware as part of the update process. The Contractor shall provide notification of known vulnerabilities affecting Contractor-supplied or required Operating System, application, and third-party software within a pre-negotiated period after public disclosure.

For any hardware or software items that are required to be serviced or repaired remotely, the Contractor shall isolate the item prior to non-local maintenance and diagnostic services, and shall sanitize the item with regard to potentially malicious software before removal and after the service is performed before reconnecting the item to the control system.

The Contractor shall recommend spare parts for the controls systems as part of the Vendor Recommended Spares listing to be able to maintain and repair the systems within 24 hours of a failure.

All information assurance (IA) and IA-enabled information technology products (e.g. servers, operating systems, routers, firewalls) shall be those that are on the approved National Information Assurance Partnership (NIAP) list.

10. FIREWALLS

The Contractor shall provide firewalls and firewall rule sets between network zones or provide firewall rule sets if the firewalls are not provided by the Contractor. The Contractor shall provide firewall rule sets and/or other equivalent documentation. The basis of the rule set shall be “deny all,” with exceptions explicitly identified by the Contractor.

The Contractor shall change default passwords during implementation. Likewise, unnecessary default accounts shall be deleted or deactivated during implementation. No password shall be hardcoded into system files. The Contractor and its subcontractors shall assist the Government in changing delivered passwords upon completion of the installation.

11. IDENTIFICATION AND AUTHENTICATION

The control systems shall uniquely identify and authenticate organizational users. The control systems shall implement multifactor authentication for access to administrator accounts.

The control systems shall implement replay-resistant authentication mechanisms for network access to administrator accounts. If the control system has role-based privileges, the system shall be configured with a minimum of a User role and an Administrator role. Security functions, such as account creation and configuring permissions, shall be limited to the Administrator role.

The control systems shall implement replay-resistant authentication mechanism for administrator accounts.

The control system shall uniquely identify and authenticate all devices before establishing local and network connections. The control system authenticates any devices not a part of the configuration before establishing local or network connections using bidirectional authentication.

For password-based authentication, the control systems shall:

a) Enforce minimum password complexity of mixed case sensitivity, minimum 15 characters, mix of upper-case letters, lower-case letters, numbers, and special characters

b) Enforce at least 8 changed characters when new passwords are created

c) Store and transmits only cryptographically-protected passwords

d) Prohibit password reuse for 5 generations

e) Require password reset every 60 days

f) Allow the use of a temporary password for system logons with an immediate change to a permanent password User accounts shall be locked out after 5 failed logon attempts; locked-out accounts shall be disabled until it is reset by an administrator or until the lockout duration for the account has expired.

The Contractor shall ensure that unencrypted static authenticators are not embedded in control systems' applications or access scripts or stored on function keys.

12. SYSTEMS AND COMMUNICATIONS PROTECTION

The control system shall separate user functionality, including user interface services, from management functionality by either physical or logical means. This can be achieved by using different computers, different central processing units, different instances of operating systems, different network addresses, virtualization techniques, or combinations of these or other methods, as appropriate.

The control systems shall isolate security functions from non-security functions by controlling access to and protecting hardware, software, and firmware that perform those security functions.

The control systems shall implement residual information protection by preventing object reuse between users of a shared resource.

The control systems shall protect against or limit the effects of the following denial of service attacks: consumption of scarce, limited, or non-renewable resources; destruction or alteration of configuration or configuration information; physical destruction or alteration of network components. Compensating controls shall include ensuring a loss of communication results in the systems operating in a nominal or safe mode. The systems shall restrict the ability of individuals to launch denial of service attacks on other components or information systems outside the enclave boundary. Individuals shall not be able to connect and transmit arbitrary information on the transport medium. The control systems shall be managed by establishing usage priorities, quotas, partitioning, and so forth, so that sufficient capacity is available to counter information flooding denial of service attacks. A tool shall be selected and employed to detect indicators of denial of service attacks against the systems and produce information that indicates if sufficient resources exist to prevent denial of service attacks.

Where possible, the control system shall provide a display banner to users that the system is a DOD information system and contains the information contained in Directive-Type memorandum 08-060 “Policy on Use of DoD Information Systems – Standard Consent Banner and User Agreement”. Where possible, the system shall not allow users to proceed until the user accepts the agreement.

13. CONFIGURATION MANAGEMENT

The Contractor shall develop, and document a current baseline configuration at delivery of the control systems to be maintained under configuration control. The Contractor shall review and update the baseline configuration of the control systems as a result of updates and patches. When patches are required, they shall be tested to determine the potential for and acceptability of identified impacts generated by the patches. The Contractor shall provide the baseline configuration to the Government to maintain an up-to-date, complete, accurate, and readily available baseline configuration of the control systems to support rollback.

The Contractor shall test, validate, and document changes to the control systems before implementing the changes on the operational system. The control systems shall issue audible alerts and notifications if baseline configurations are changed in an unauthorized manner.

For changes to control systems hardware and software configurations, the Contractor shall submit these changes to the Government as part of the Configuration Management. The Contractor shall perform configuration management during system implementation and operation; document, manage, and control the integrity of changes; implement only approved changes to the system; document approved changes to the system and the potential security impact of such changes; and track security flaws and flaw resolution within the system.

14. CONTINGENCY PLANNING

Control systems shall contain automated back-up capability that does not cause the system to fail existing timing or performance requirements. System-level information (e.g. system state information, system data necessary to recover/restore system operation, and user data) shall be included in backups.

The Contractor shall provide system restoration media and procedures to recover or completely rebuild disabled system components using only the material provided and routine backup data. Back-ups, other historical files, and network storage shall be protected by a Data-At-Rest solution approved by NIAP, such as Microsoft BitLocker.

15. TESTING

The Contractor shall assist the Government in performing cybersecurity testing. The Contractor shall provide on-site attendance and support by knowledgeable subcontractor personnel for all supplied control systems during this testing.

16. AUDIT AND ACCOUNTABILITY

In addition to the other audit requirements identified elsewhere, the control system shall generate audit records for the following events:

a) Account creation

b) Account modification

c) Enabling, disabling, and removal actions related to each account

d) Notification to the system administrator

e) Changes to the approved baseline configuration

f) Successful and unsuccessful logon attempts

g) Concurrent logons from different workstations

h) All program initiations

i) All direct access to the information system

j) All kernel module load, unload, and restart

k) Application-level failures

l) Denial of access resulting from excessive number of logon attempts

m) Data required to audit the possible use of covert channel mechanisms

n) Privileged activities and other system level access

o) Successful and unsuccessful attempts to access security files

p) Blocking a user ID, terminal or access port, and the reason for the action

q) Activities that might modify, bypass or negate safeguards controlled by the system

r) System configuration file changes

The control system shall generate audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event.

The auditing system shall provide an audit reduction and report generation capability that (1) supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents; and (2) does not alter the original content or time ordering of audit records. The control systems shall provide the capability to automatically process audit records for events of interest based upon selectable, event criteria.

The auditing system shall use internal system clocks to generate time stamps for audit records that can be mapped to Coordinated Universal Time. The audit records shall be logged in one second increments.

The audit system shall off-load audit records to an alternate system or media, which shall be capable of storing a minimum of 1 year of audit data.

image1.jpeg image2.jpeg

File details come from the government source that posted it. Updated .