Att-1 METS Airplane PWS Appendix A-Cyber Security Plan 21July2021.pdf
PDF 191 KB Posted
- Attached to
- SOURCES SOUGHT NOTICE -- MULTI-ENGINE TRAINING SYSTEM (METS) AIRCRAFT PROCUREMENT Federal contract opportunity
- Solicitation number
- N00019-20-R-0071
About this file
This notice announces a draft request for proposal for a multi-engine training system aircraft procurement. The Navy seeks industry feedback on the draft RFP by October 18th, 2021 and plans a pre-solicitation conference the week of November 1st, 2021. Only new aircraft will be considered for the multi-engine training system, with the goal of facilitating student naval aviator training through 2055. The cybersecurity plan appendix to the RFP outlines requirements for contractors to utilize current security best practices, ensure networks and applications are compatible with the Navy, and obtain PKI certificates for electronic collaboration tools. Contractors must also deliver a cybersecurity implementation plan and ensure any delivered systems or software meet standards for input validation, integrity checking, and supply chain risk management.
View the file
Other files for this federal contract opportunity
Show all 34
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Program Executive Office - Tactical
PEO (T)
PMA-273
Request for Proposal (RFP)
Cybersecurity Plan (CSP)
Dated: 21 July 2021
Version 4.0
Approved by: _____________________________
PISSM
Program Information System Security Manager
DISTRIBUTION STATEMENT A: Approved for public release: distribution unlimited.
The contractor shall generate and deliver a Cyber Security Implementation Plan (CSIP) to address the requirements contained within the PMA-273 CSP and CSIP Contract Data Requirements List (CDRL) by the authority of Data Item Description (DID) - DI-MGMT-82002B. This DID contains the format, content, and intended use information for the data product resulting from the work task described by the contract.
For all software to be delivered to the Government the contractor shall adhere to the following requirements contained within the PMA-273 CSP and System-Software CDRL by the authority of DID - DI-MISC-80508B.
This DID contains format and content preparation instructions for the data product generated by the specific and discrete task requirement as delineated in the contract.
Below is an excerpt from the PMA-273 CSP. Contractors shall consider the following when bidding on PMA- 273 contracts:
A. Ensure their networks and applications are compatible with USN.
B. Ensure current industry best practices are utilized.
C. Ensure ECA PKI certificates are procured and utilized for personnel supporting the contract.
D. Ensure email is protected with PKI.
E. Ensure DOD data is protected while at rest.
F. If delivering a system that it meets all Risk Management Framework requirements (DoDI 8500.01).
G. Ensure there is a Cybersecurity professional with industry training to serve as a POC with Government officials.
H. Ensure PKI certificates are utilized for all electronic collaboration tools.
I. If delivering software that it meets industry standards of: validation input, integrity checking, software assurance, and supply chain risk management.
File details come from the government source that posted it. Updated .