MSP-08-007 FISMA AUDIT.doc

DOC document 83 KB Posted

Attached to
Information Security Program Review Federal contract opportunity
Solicitation number
MSPB-08-007
Issued by
Merit Systems Protection Board

About this file

Request for quotations for MSPB Security Audit.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Information Security Review

Request for Quotations

MSP-08-007

FISMA Compliance

And Review of the

MSPB Information Security Program

May 2008

Table of Contents

Section
Page

Background

Environment Scope of Work 3.1 Tasks 3.1.1 Overview 3.1.2 Review and Assessment 3.2 Programs and Systems 3.2.1 Description of Systems 3.2.2 Information Maintained at Other Agencies 3.3 Reporting Requirements 3.4 Time Requirements 3.5 Period of Performance 3.6 Work Site 3.7 Employee and Data Accessibility 3.8 Travel 3.9 Confidentiality Contracting Officer’s Technical Representative Payment How to Submit Quotations Evaluation and Award

Attachment 1 Description of MSPB Hardware/Software Attachment 2 Table of Authorities Request for Quotation

Review of MSPB Information Security Program

1 Background

The Merit Systems Protection Board (MSPB or the Board) is an independent quasi-judicial Federal agency charged with protecting the integrity of the Federal merit employment systems. The Board is responsible for hearing and adjudicating employee appeals of adverse personnel actions such as removals, suspensions, and demotions, as well as certain other employment and retirement matters. The Board also hears and adjudicates cases brought by another independent Federal agency, the Office of Special Counsel, involving alleged abuses of the Federal merit systems. In addition to its adjudicatory responsibilities, the Board is responsible for conducting studies of the civil service and other Federal merit systems.

Given the nature of the Board’s two statutory programs, its operations do not present a substantial information security risk. The information maintained by MSPB consists principally of Federal employee personnel data that is used in the adjudication of individual cases and in studies of the Federal merit systems. The agency’s adjudicatory case records constitute a system of records subject to the Privacy Act of 1974 (Public Law No. 93-579). The MSPB Information Security Program, therefore, is designed to ensure the protection of data maintained in the agency’s automated systems from unauthorized access, as well as to ensure the availability of the systems used by MSPB employees to accomplish their work.

2 Environment

The bipartisan Board consists of a Chairman, a Vice Chairman, and a Member, who are appointed by the President and confirmed by the Senate. The MSPB headquarters office is located at 1615 M Street, NW, Washington, DC. There are also regional/field offices located in the following cities:

· Alexandria, VA

· Atlanta GA

· Chicago, IL

· Dallas, TX

· Denver, CO

· New York, NY

· Philadelphia, PA

· San Francisco, CA

2.1 MSPB has approximately 235 employees, most of whom are attorneys. Just over half of the agency’s workforce is located at headquarters. The balance of MSPB’s workforce is in the regional/field offices, which range in size from eight to 17 employees. The agency does not have, and is not required by law to have, an Inspector General. Agency responsibilities under the IG Act are delegated to the Office of General Counsel.

2.2 SCOPE OF WORK

2.3 TASKS

2.4 Overview

2.5 The Federal Information Security Management Act (FISMA) was enacted as Title III of the E-Government Act of 2002, Public Law 107-347. To comply with FISMA regulations, independent contractors have performed annual audits of the MSPB security program since FY2003. These processes must follow a combination of Federal Information Processing standards (FIPS) documents, the special publication SP-800 series issued by the National Institute of Standards and Technology (NIST), and other legislation pertinent to federal information systems.

2.6 MSPB has submitted quarterly and annual reports on its Plan of Action and Milestones (POAM) for correcting information security weaknesses identified in either the contractor's annual reviews or in internal agency reviews. The annual FISMA report submitted to OMB since FY2003 included the agency component report, the IG report, and the independent contractor's evaluations. The FY2007 audit was preformed by NIT, Inc. The annual evaluations and all reports submitted to OMB from FY03 through FY07 will be available to the contractor when they conduct the audit for 2008.

2.7 Review and Assessment

2.8 MSPB requires the services of an independent contractor to conduct an evaluation of the MSPB Information Security Program sufficient to meet FISMA regulations, and to prepare the IG portion of the annual report to be submitted to OMB. The audit should determine whether MSPB's information systems meet the minimum security requirements defined in FIPS 200 through the use of the security controls specified in NIST SP 800-53, Guide for Assessing Security Controls for Federal Information Systems.

2.9 The contractor's evaluation shall include “testing of the effectiveness of information security policies, procedures, and practices of a representative subset of the agency's information systems” (44 U.S.C. § 3545(a) (2) (A )). MSPB has a single general support system, as described in Section 3.2, Programs and Systems.

2.10 The Contractor shall prepare a report that describes the results of the review, identifying any deficiencies and shall ensure that the report conforms to OMB's most recent FISMA reporting instructions for Inspectors General.Programs and Systems

2.10.1 Description of Systems

2.10.2 MSPB has identified four applications that comprise its General Support System. These applications are available to each MSPB employee and support MSPB's two statutory programs, as well as its administrative and management functions:

2.10.3 Case Processing System – This system currently consists of the Document Management System (DMS), the Document Assembly System (DAS), the Case Management System (CMS), and e-Appeal. The case management system uses Law Manager, a commercial, off-the-shelf product configured for MSPB use, and is referred to as CMS/LM. E-Appeal, an interactive web-based application for filing appeals with the Board was implemented in October 2003. The DMS, DAS, and CMS/LM operate on Windows XP desktops, Windows 2003 and UNIX servers, and ORACLE DBMS. Perot Systems, the developer of the software, hosts E-Appeal.

2.10.4 Exchange/Outlook – This is MSPB's current e-mail system. Outlook and Exchange operates on Windows XP desktops and Windows 2003 servers. During the current fiscal year, MSPB has migrated a number of legacy application databases, such as address books, calendars, instructions, publications and training records from Lotus Notes to Microsoft Exchange.

2.10.5 Computer and Telecommunications Center – This is the physical facility at MSPB headquarters and includes the hardware and software for the agency's information systems: Windows 2003 and Active Directory servers, UNIX server for Law Manager, CISCO routers for WAN connection with regional offices, external connectivity through dial-up modems or VPN, VPN access to and from other agencies (see section 3.2.2), and Blackberry wireless access to electronic mail.

2.10.6 Web Systems – This consists of an internal web portal and public web services hosted on servers at MSPB headquarters. The internal portal allows MSPB employees access to data stored in CMS as well as providing an access point for other agency news, updates and documents. It operates on Windows 2003 servers using Microsoft .Net framework.

2.10.7 The Case Processing System supports the agency's adjudication program. All cases docketed are entered into CMS/LM and all events that transpire during the processing of a case are entered as they occur. Case processing documents are created in the DAS, which partially automates the document assembly process, and stored in the DMS and also accessed by MSPB employees through the web portal. The external web servers also allow non-classified documents in DMS, such as published Board decisions, to be accessed by the general public.

2.10.8 Systems are available to employees in the MSPB headquarters through a Local Area Network (LAN) and to employees in the regional/field offices through a Wide Area Network (WAN). All employees have desktop PCs, and employees on flexible schedules are equipped with laptop computers to access MSPB systems using VPN or dial up access. Employees may also check out laptop computers to access MSPB while on official travel. All employees are also provided with Internet access when connected to the LAN/WAN.

2.10.9 A detailed description of MSPB hardware and software assets is in Attachment 1.Information Maintained at Other Agencies

The MSPB has interagency agreements with the Department of the Treasury’s Bureau of the Public Debt (BPD) for accounting services; USDA’s National Finance Center (NFC) for payroll services; and USDA’s Animal and Plant Health Inspection Service (APHIS) for human resources management services. MSPB staff make programmatic site visits to these agencies regularly. However, because the MSPB is a small agency with limited resources, it relies on the representations of these agencies that they regularly receive audits attesting that they are adequately secure and meet the requirements of appropriate security law and policy. Each of these agencies is an Executive Branch agency subject to the information security requirements of FISMA.

2.11 Reporting Requirements

The Contractor shall inform the Information Resources Management (IRM) Deputy Director and Information Systems Security Officer (ISSO), Nick Ngo and Tim McAleer respectively, via e-mail when a change in direction, emphasis, or time frame is needed. The Contractor shall also contact Rosalyn Wilcots, Legislative Counsel, Office of General Counsel, as frequently as is necessary—but at the minimum of 30-day intervals—to advise her of the status of the review and assessment. The OGC Legislative Counsel will be responsible for notifying Charlie Roche, Director, Office of Financial and Administrative Management (FAM), of any procurement issues involved with the above.

2.12 Time Requirements

The Contractor shall begin the review within 7 days after the contract is awarded. The period of performance is not expected to exceed 60 days (including the two 7-day review cycles); however, this time frame may be revised as the Contractor determines the amount of written documentation required.

The Contractor shall submit a draft report to the COTR (see section 4, Contracting Officer’s Technical Representative) within 14 days after completion of the Contractor’s review. The COTR will be afforded up to 7 days after receipt of the draft report to review, critique, and offer suggestions on the proposed draft, unless otherwise mutually agreed upon by both parties (the COTR and the Contractor). The Contractor shall deliver a final report to the COTR within 15 days after the submission of suggestions to the Contractor, unless otherwise mutually agreed upon by both parties. The final report is to be delivered to the COTR no later than September 15, 2008. The draft report will be delivered electronically and the final report will be delivered in CD format along with twenty bound and printed copies.

2.13 Period of Performance

The base period of award shall be for one audit/one year (FY-2008). At the Government’s discretion, awards may be issued for two additional audits/years (FY-2009 and 2010) in accordance with FAR clause 52.217-9, Option to Extend the Term of the Contract (Mar 2000). Contractor will be provided with preliminary written notice of the Government’s intent to extend at least 60 days before the contract expires. This preliminary notice does not commit the Government to an extension.

WORK SITE

MSPB will provide the Contractor on-site workspace at MSPB headquarters, on a space available basis. However, work that can be performed at the Contractor's site is authorized as is deemed appropriate. All required data will be made available to the Contractor at the MSPB headquarters location.

EMPLOYEE AND DATA ACCESSIBILITY

MSPB employees will make themselves available to the Contractor to respond to inquiries and requests for data. Employees will provide the Contractor access to records, files, data, and documentation relevant to this review.

TRAVEL

Travel to the MSPB headquarters in Washington, DC, and the Washington Regional Office in Alexandria, VA, shall be required as necessary during the performance of the task, at the Contractor's expense. No other travel is expected.

CONFIDENTIALITY

The Contractor shall hold information concerning MSPB employees in the strictest of confidence. Disclosure of such information is permitted only to Contractor personnel working on this contract.

CONTRACTING OFFICER'S TECHNICAL REPRESENTATIVE

At the time of award, the Contracting Officer may designate a Contracting Officer's Technical Representative to work with the Contractor during performance of the contract. This individual will not be authorized to order or accept work beyond the scope of the contract or to obligate in any way additional work under or outside the contract. That authority is reserved strictly to the Contracting Officer.

PAYMENT

The Contractor shall provide a work plan and cost proposal to the FAM Director. Upon an award, the Board anticipates the following payment schedule (negotiable):

50% of the stated costs upon receipt of a written draft by the FAM Director; and

50% of the stated costs upon acceptance of the final report by the FAM Director.If payment by credit card is not acceptable, the Contractor must be registered in the Central Contractor Registration System (CCR) before any payments may be processed. Information on the CCR program may be obtained through the Contracting Officer’s Technical Representative.

3 How to Submit Quotations

Interested potential Contractors may submit two copies of quotations to the Board by mail, e-mail, or FAX.

Address quotations to:

Merit Systems Protection Board

ATTN: Veronica Bullock, Contracting Officer

1615 M Street, NW, Suite 500

Washington, DC 20036 quotation@mspb.gov

202-653-7821 (FAX)

202-653-6772, ext. 1120 (voice)

Quotations must be received by the Board no later than close of business (4:45 PM) on June 30, 2008.

Quotations shall include:

· A corporate profile or resume showing Contractor’s experience in this field (particularly any experience conducting FISMA reviews and preparing the IG portion of the FISMA report), including one or more references;

· Names and resumes of persons who will conduct the review;

· Name, mailing address, e-mail address, telephone number(s), and resume of Contractor’s proposed Project Manager;

· An outline of Contractor’s proposed work plan; and

· A firm fixed price including a breakdown by labor category with corresponding hours and rates. Separate pricing should be provided for the base year and the two option years.

4 Evaluation and Award

Award for the base audit will be made to the firm/individual offering the best value to the Government, price and other factors considered. Consideration will be given to contractors on GSA Schedule. Any subsequent award against the two optional years will be made at the discretion of MSPB and will depend on the availability of funds and the performance of the contractor.

ATTACHMENT 1

MSPB Hardware

2 UNIX Sun v440 server w/3310 storage arrays 35 HP Proliant ML and DL servers 4 HP Proliant BL blade servers 10 CISCO routers (2610 and 3845) 6 CISCO LAN Switches (6500 and 2950) 1 CISCO PIX Firewall (515E) 1 Network Access Storage device (Quantum SNAP)

1 CISCO IDS 4205

1 CISCO VPN 3005

1 CISCO RAS 3640

3 CISCO Wireless Access Point 1 Juniper SA 1000 SSL appliance 60 DELL desktops 180 Lenovo ThinkPad laptops 150 HP LaserJet printers 43 Blackberry PDAs

MSPB Software

WindowsXP (desktops and laptops) Microsoft Office 2003 Microsoft Active Directory Windows 2003/2000 Server Solaris 9 Lotus Domino/Notes 6.5 Oracle 9 DM DocsFusion/Hotdocs Law Manager 2000 CISCO Secure VPN client RUMBA Telnet Veritas BackupExec Veritas NetBackup Business Server for Solaris Symantec Anti-virus 9.0 c.Support (help desk tracking) MailMarshal (mail content/spam control)

ATTACHMENT 2

Table of Authorities

OMB Circular No A-130, Management of Federal Information Resources, multiple revisions. Securing Agency Information Systems, as analyzed in Appendix IV OMB Circular No. A-123, Revised, Internal Control Systems.

OMB Circular No. A-127, Revised, Financial Management Systems.

Public Law (P.L.) 96-511, Paperwork Reduction Act of 1980, P. L. 99-500, Paperwork Reduction Act of 1995.

P.L. 93-579, Privacy Act of 1974, and Privacy Act, 5 U.S.C. Sec. 552a.

P.L. 97-255, Federal Manager’s Financial Integrity Act of 1982.

P.L. 100-235, Computer Security Act of 1987 P.L 104-13, Paperwork Reduction Act of 1995

P.L. 105-277, Government Paperwork Elimination Act (GPEA)

P.L. 107-347, E-Government Act of 2002, Federal Information Security Management Act (FISMA)

Federal Personnel Manual (FPM), Chapter 732, Personnel Security..

Executive Order 13011, Sec 2 Responsibilities of Agency Heads (3) & (5).

Executive Order 13101, Part I, Section 101.

MSPB Notice, Appointment, Chief Information Officer.

National Defense Authorization Act for Fiscal Year 1996, Section 2, Division E, Information Technology Management Reform [Also known as Clinger/Cohen Act].

PAGE

ii

File details come from the government source that posted it. Updated .