NGT_CDRL_Attachment_4-DITPR-DON_Questionnaire.docx

DOCX document 32 KB Posted

Attached to
Next Generation Troposcatter Federal contract opportunity
Solicitation number
M67854-19-R-2000
Issued by
United States Marine Corps

About this file

This document contains a questionnaire related to a Marine Corps information technology system. The questionnaire requests details on the system such as its name, users, interfaces, security certification status, and compliance with standards including FISMA, E-Authentication, and SFIS. It appears to be collecting baseline information on the system for reporting and oversight purposes. The document does not specify any required products or services, response dates, or federal agencies involved.

CDRL Attachment 4. *Note, as of Amendment 0002, CDRL Attachment 3 has been marked "reserved" and the reference in CDRL A00J has been removed.

View the file

Other files for this federal contract opportunity

Other files attached to Next Generation Troposcatter, newest first.
File Type Posted
M67854-19-R-2000_Amendment_0005.docx DOCX document
M67854-19-R-2000_Amendment_0004.docx DOCX document
M67854-19-R-2000_Amendment_0003.docx DOCX document
Q&A.pdf PDF
NGT_CDRL_Attachment_1.docx DOCX document
M67854-19-R-2000_Amendment_0002.pdf PDF
NGT_CDRL_Attachment_8-Change_Proposal_Form.pdf PDF
NGT_CDRL_Attachment_6-Operator_Manual_Content_Selection_Sheet.docx DOCX document
M19-R-2000_DD_254_CONT_Sheets.pdf PDF
NGT_CDRL_Attachment_2.docx DOCX document
M67854-19-R-2000-0002_NGT_CDRLs_v1.docx DOCX document
NGT_CDRL_Attachment_5-LPD_Attribute_Selection_Sheet.docx DOCX document
NGT_CDRL_Attachment_7-Maintenance_Manual_Content_Selection_Sheet.docx DOCX document
M67854-19-R-2000-0002_Attachment_3_v1.docx DOCX document
M67854-19-R-2000_Amendment_0001.docx DOCX document
M67854-19-R-2000_Attachment_4_-_PSPEC.pdf PDF
M67854-19-R-2000_Attachment_5_DD_254.pdf PDF
M67854-19-R-2000_Attachment_3_-_SB_Part_&_Comm_Strat.docx DOCX document
M67854-19-R-2000_Exhibit_1_CDRLs.docx DOCX document
M67854-19-R-2000_Attachment_1_-PSPEC_Compliance_Matrix.xlsx XLSX spreadsheet
M67854-19-R-2000_NGT_RFP.docx DOCX document
M67854-19-R-2000_Attachment_2_-_SB_Subk_Record.docx DOCX document
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CDRL Attachment 3 – DITPR-DON Questionnaire

* System Name:

*Acronym:

*Record Type:
System
*Component:
USMC
Sub-Organization:
USMC

Primary MA-Domain:

DBS:

BIN:

Explain (for BIN:9990)

ACAT Code:

Transition Plan State:
Core

System_Operation:

Total Users:

**Type of IT/NSS:

Use modified COTS:

Business Function:
For DBS Systems Only

Investment Stakeholders:

DITPR ID

Description:

DITPR-DON Unique Information

*FAM:

DON Record Type:

*Echelon II:
N00027 - HQ USMC
Activity Code:

*BSO:

*Resource Sponsor:
USMC

AIS.EXT:

*Active/Inactive:
Active - Record
*Portal Development Software:
N00027 - HQ USMC

Comments:

*Host Portal:

Other Host Portal:

General System Info

Relation-ship
DITPR-DON ID
Acronym
System Name
Echelon II
Relationship Comments

List Associated systems here

N00027 USMC

Using components

Component
Current
Future
As of Date
Investment Stakeholder

USMC

Yes

Points of Contact

Role
Contact Name
Title
Organization/ Activity
Phone
DSN
E-mail

Functional Area Manager (FAM)

Program Manager (PM)

Technical Manager TM

Security Manager (ISSM)

Role
Contact Name
Title
Organization/ Activity
Phone
DSN
E-mail

Lifecycle Status

Lifecycle Phase
Start Date [YYYYMMDD]
End Date [YYYYMMDD]
Comments
Last Edited

Operations & Support

Mission Criticality Questions Mission Critical/Mission Essential/Mission Support

Mission Criticality:

IT Contingency Plan In Place?:

Number of interfaces to other systems?:

Core - Trigger Questions Federal Information Security Management Act (FISMA)

*Security Certification & Accreditation Required:
Yes

Not Apply Explanation:

E-Authentication

*Browser Based:

*External Facing:

*End User Authentication Required:

*Authentication Method:

Privacy Impact Assessment (PIA)/ Privacy Act (PA)

*Is Personal Identifiable Information (e.g., medical, financial, etc.) Contained in the System:

*Does this system (or initiative) contain Social Security Numbers (SSNs) (full or truncated) or use SSNs in the system:

Enterprise Transition Plan (ETP)

*Is the System in Enterprise Transition Plan (ETP):

Information Assurance (IA)

*PK-Enabled:

Yes, system is PK-Enabled for user authentication, digital signature and encryption Your network/system/application is Public Key Enabled if you use CACs, Alt Tokens, or software certificates and are able to invoke one or more of the following public key cryptography based functions: digital signature generation; digital signature verification; encryption; decryption.

SFIS

*Accounting System or Financial Feeder System:

IRB and Modernization/Certification

IRB Interest Program:
NO

*Does the system have any development/modernization (dev/mod) funding:

Joint Capability Areas

Assoc
JCA Title
Assigned By
Date

LEAD

SEC

SEC

SEC

SEC

SEC

SEC

SEC

FISMA

1) *Accreditation Required:
Yes

2) **Not Apply Explanation:

3) MAC Code:

4) Confidentiality Level:

4a) Processes NNPI:

5) IA Record Type:

6) Accreditation Status:

7) Accreditation Vehicle:

8) Accreditation Date:

9) Accreditation Expiration:

10) Is there a POA&M with open weaknesses:

10a) Is the system operating with one or more security weaknesses that are currently greater than 120 days beyond the planned remediation date in the POA&M:

10b) Is the system operating with one or more security weaknesses that are currently 90 to 120 days beyond the planned remediation date in the POA&M:

11) IT Contingency Plan In Place:

Note: Answer to question 12) (below) should be consistent with this answer

12) IT Contingency Plan Test Date:

13) Security Controls Tested:

14) Date Annual Security Review:

15a) ** Current IATS Reference Number:

15b) Additional/Prior IATS Reference Numbers:

16a) **DAA Letter Serial Number:

16b) Additional ATO/IATO Tracking Numbers:

17) Designated Approval Authority (DAA) Name:
LETTEER,RAY A.
Designated Approval Authority (DAA) Title:
GS-15
Designated Approval Authority (DAA) Organization:
HQMC C4I IA
Designated Approval Authority (DAA) Phone:
(703) 693-3490

Designated Approval Authority (DAA) DSN Phone:

Designated Approval Authority (DAA) Email:
ray.letteer@usmc.mil

E-Authentication Questions 1), 2), 3), 4) are Required for ALL Systems.

Questions 5) - 29) Required if Question 1) and 2) Answers are 'Yes' and 3) is 'Partially' or 'All'.

Question 4) must be 'NA' if 3) is 'None' and can not be 'NA' if 3) is 'Partially' or 'All'.

Question 32) is Required if Question 4) Answer is 'Other'.

1) Browser Based:

2) External Facing:

3) End User Authentication Required:

4) Authentication Method:

5) Risk Assessment Completed/Planned Date:

6) Assurance Level:

7) Percent of Users Requiring Level 1 or 2 Assurance:

8) Percent of Users Requiring Level 3 or 4 Assurance:

9) E-Authentication Approved Product Used:

10) Other Authentication Products Used:

11) E-Authentication Architecture Status:

12) Status in POA&M in Joining the E-Auth Arch:

13) Architecture Implementation Date (FYxx):

14) Potential Citizen Users Requiring Authentication:

15) Potential Business Users Requiring Authentication:

16) Non-Agency Government Users Req. Auth.:

17) Total Number of Potential Internal Agency Users:

18) Internal Agency Users Functioning as a Federal Empl.:

19) Total E-Authentication Transactions:

20) Logins/Year Performed by External Users:

21) Online Citizen Users Requiring Authentication:

22) Online Business Users Requiring Authentication:

23) Online Non-Agency Users Requiring Authentication:

24) Online Internal Agency Users, Functioning on Behalf of the Agency, that Require Authentication:

25) Average Annual Online Usage Growth Rate Through FY10:

26) Description of Citizen Customer Group(s) Being Authenticated:

27) Description of Business Customer Group(s) Being Authenticated:

28) Description of Government Customer Group(s) Being Authenticated:

29) System URL: *Required for All Browser Based

30) Access Controls:

31) Administrative Controls:

32) Authentication Comments:

Privacy Impact Assessment (PIA)/ Privacy Act (PA) *Is Personally Identifiable Information (e.g., medical, financial, etc.) Contained in the System:

*Does this system (or initiative) contain Social Security Numbers (SSNs) (full or truncated) or use SSNs in the system:

*If the system contains SSNs, Answer all of the following Questions

Is the continued collection or use of SSNs (full or truncated) required for this system?

A memo justifying continued collection of the SSN, signed by a Flag/SES or individual given by direction signature authority, must be uploaded in the DITPR DON to the Document section. A blank justification memo can be downloaded from the Ref Docs section under the Reference Tab.

Provide the name, rank and title of the person signing the justification memo:

Provide the date of the justification memo:

Could another unique identifier (e.g., the DoD Identification Number, or Benefits Number) be substituted for the SSN:

Identify the unique identifier:

Estimated date substitution will occur:

When will the collection of the SSN be eliminated from this system:

Select the primary legislative or legal justification for using SSN:

What is the specific legislative or legal reference that justifies using SSN or Explain for 'Other Cases' and 'Not Acceptable Use' selections:

Does the system use any DD, SD, or component-wide, paper-based or electronic, forms for input/output:

If such Forms are used, do any contain SSNs:

Please provide the following for all INPUT forms that contain SSNs:

Provide Form Designations and Number, Form Title and (if applicable) OMB Control Numbers

Please provide the following for all OUTPUT forms that contain SSNs:

Provide Form Designations and Number, Form Title and (if applicable) OMB Control Numbers

Privacy Impact Assessment (PIA)

Privacy Impact Assessments (PIAs) are NOT required if:

The system is a National Security system (including systems that process classified information)

The system does not collect, maintain, use or disseminate personally identifiable information (PII)

PIAs are required when PII is collected, maintained, used or disseminated about members of the public, Federal employees, contractors, or foreign nationals employed at U.S. military facilities internationally.

--PIA Required:

PIA Reviewed/Approved by Component CIO:

PIA Submit OMB (for Exhibit 53s and 300s):

PIA Submitted to OMB Date (for Exhibit 53s and 300s):

PIA Comments:

Privacy Act (PA)

Is Personally Identifiable Information (e.g., medical, financial, etc) retrieved from the system by name or other identifier (e.g., SSN, fingerprint)?:

Has a Privacy Act system notice been published in the Federal Register (FR)?:

If published, what is the date of publication?:

What is the System Identifier for the system notice?:

No notice was published in the FR explanation:

SFIS

*Accounting System or Financial Feeder System:

If the system does not support SFIS, explain.

**Has there been an independent third party assessment of FFMIA compliance?

If not, what is the projected date for the review?

**Has an SFIS Compliance Checklist been filled out?

If so, what is the latest version of the checklist which was filled out?

**Has an SFIS Implementation Plan been provided?

**What is the projected date for SFIS Full Operational Compliance?
Date Format: 20130215

**Has a Standard Line of Accounting Implementation Plan been filled out?

If a Standard Line of Accounting Implementation Plan has not been filled out, please explain.

With what systems will this system be interfacing?

ID
Name
Acronym
Comp.
Relation-ship
Dates

What systems will this system replace?

**Has the System undergone an ODCMO/OUSD(C) SFIS Validation?

Date Format: 20130215

SFIS/USSGL Validation Questions (accessible by DCMO only)

1. How many SFIS business rules are applicable to the system?

2. With how many applicable SFIS business rules is the system compliant?

3. Percentage compliant with applicable SFIS business rules:

4. How many DoD Reporting Chart of Account values are applicable to the system?

5. With how many applicable DoD Reporting Chart of Account values is the system compliant?

6. Percentage of compliance with applicable DoD Reporting Chart of Account values?

7. How many DoD Posting Chart of Account values does the system have?

8. How many Posting Accounts are SFIS/USSGL compliant?

9. Percentage of the system's posting Chart of Accounts which are SFIS/USSGL compliant?

10. What is the number of transactions tested for proper posting logic?

11. Of the sample, what is the number of transactions which have proper posting logic?

12. Percentage of transactions tested have proper posting logic?

13. How many system-to-system data exchanges does the system have?

14. How many system-to-system data exchanges will need to be SFIS Compliant?

15. How many system-to-system data exchanges currently are SFIS Compliant?

16. Does the system transmit an SFIS compliant trial balance?

17. Have the system's internal controls been tested?

If so, what is the finding?

18. Has the system been reviewed to ensure proper documentation is maintained to support the transaction?

If so, what is the finding?

System Infrastructure *Domain on which system operates?

If not '.mil' or'.gov' describe, providing rationale/justification:

GIG Domain Waiver requested? (Y/N)
---
Date granted:

Date expires:

*Network(s) on which system operates?

If "Other" describe, providing rationale/justification:

*Classification level of network
---
GIG Network Waiver requested? (Y/N)
---
Date granted:

Date expires:

Hosting Environment

*Hosting Environment

*Enter name and location of data center:

*Host Operation:

*Data Center Provider:
---
If commercial or Other, describe:

Information Assurance / Public Key Infrastructure (PKI) *PK-Enabled:

PK-Enabled Date:

If system is not currently PK-enabled, but is required to be PK-Enabled, for what will it be PK-Enabled?

To Be PK-Enabled Date:

*Explain PK-Enabled Answer:

Note: To help in filling out this section, please refer to the Frequently Asked Questions and other reference documents located in the "Ref Docs" section, under Secure Hash Algorithm-256 (SHA-256) Migration.

Internet Protocol Version 6 (IPV6) Compliance

*Internet Protocol Version 6 (IPV6) enabled?:

Host Based Security System (HBSS) Compliance

*Host Based Security System (HBSS) enabled?

Select all HBSS components that have been implemented:

If Other or Not Required selected, explain:

If not yet HBSS compliant, enter date HBSS will be fully implemented:

Secure Hash Algorithm (SHA-256) Compatibility

*Is this system fully SHA-256 comp

Will this system be upgraded to full SHA-256 compatibility by the end of CY 2013:

Planned completion date for operating system (O/S) and/or other necessary upgrades that allow use of SHA-256:

UPLOAD POA&M in DITPR-DON ‘DOC’ tab to explain how you will enable system support for SHA-256 (please use SHA-256 POA&M template in Help section).

Use the name ‘SHA-256 Migration POA&M,’ preceded by the name of your network/system/application (e.g., ‘SYSTEMNAME SHA-256 Migration POA&M’). UPLOAD

DITPR-DON to DADMS Mappings (COTS in use)

Name
Acronym
Version
DADMS

ID

File details come from the government source that posted it. Updated .