About this file

This document is a Data Item Description (DID) for a Cybersecurity Vulnerability Report. The report provides information on the current state of the network security infrastructure and the security posture. Key requirements include:

  • Reporting on unmitigated Category I, II, and III vulnerabilities, including those over 30 or 180 days old
  • Explaining why remediation was not applied to 100% of affected assets
  • Reporting monthly asset discovery results
  • Carrying open findings over 30 days to the quarterly Information Security Plan of Action and Milestones (POAM)
  • Identifying the office/organization responsible for resolving vulnerabilities
  • Identifying any additional resources required, such as purchase requirements or additional/shifted manpower

The DID is related to a sole source firm-fixed-price contract for the Marine Ammunition Knowledge Enterprise (MAKE) One Network NEO Licensing and Support, to be awarded to One Network Enterprises Incorporated. The period of performance, response date, and other specifics are provided in the attached solicitation.

View the file

Other files for this federal contract opportunity

Other files attached to Marine Ammunition Knowledge Enterprise (MAKE) One Network NEO Licensing and Support, newest first.
File Type Posted
N6426725R0001_SAM_20241017.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Source: http://assist.dla.mil -- Downloaded: 2024-09-13T18:26Z Check the source to verify that this is the current version before use.

DATA ITEM DESCRIPTION

Title: CYBERSECURITY VULNERABILITY REPORT

Number: DI-MGMT-82191 Approval Date: 20180322

AMSC Number: N9908 Limitation: N/A

DTIC Applicable: N/A GIDEP Applicable: No

Preparing Activity: SH Project Number: MGMT-2018-021

Applicable Forms: N/A

Use/Relationship: The Cybersecurity Vulnerability Report provides information on the current state of the network security infrastructure. It provides information needed to understand and improve the security posture.

This data item description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirement as delineated in the contract.

Requirements:

Format. The Cybersecurity Vulnerability Report shall be in contractor’s format. 1.

Content. The Cybersecurity Vulnerability Report shall include the following: 2.

a) Unmitigated CAT I (High and Critical) – Total

b) Unmitigated CAT I (High and Critical) – Over 30 days

c) Unmitigated CAT II (Medium) – Total

d) Unmitigated CAT II (Medium) – Over 180 days

e) Raw CAT III (Low) – Total

f) Explanation of why remediation was not applied to 100 percent of affected assets for all outstanding open remediation actions.

g) Monthly Asset Discovery Results w/delta

h) All findings open longer than 30 days will be carried over to quarterly

Information Security POAM.

2.1. POC. Identify Office/Organization responsible for resolving vulnerability.

2.2. Additional Resources Required

a) Purchase requirements

b) Additional or shift of manpower

End of DI-MGMT-82191

Source: http://assist.dla.mil -- Downloaded: 2024-09-13T18:25Z

File details come from the government source that posted it. Updated .