Exhibit A.pdf
PDF 531 KB Posted
- Attached to
- Marine Ammunition Knowledge Enterprise (MAKE) One Network NEO Licensing and Support Federal contract opportunity
- Solicitation number
- N6426725R0001
About this file
This document is a Data Item Description (DID) for a Cybersecurity Vulnerability Report. The report provides information on the current state of the network security infrastructure and the security posture. Key requirements include:
- Reporting on unmitigated Category I, II, and III vulnerabilities, including those over 30 or 180 days old
- Explaining why remediation was not applied to 100% of affected assets
- Reporting monthly asset discovery results
- Carrying open findings over 30 days to the quarterly Information Security Plan of Action and Milestones (POAM)
- Identifying the office/organization responsible for resolving vulnerabilities
- Identifying any additional resources required, such as purchase requirements or additional/shifted manpower
The DID is related to a sole source firm-fixed-price contract for the Marine Ammunition Knowledge Enterprise (MAKE) One Network NEO Licensing and Support, to be awarded to One Network Enterprises Incorporated. The period of performance, response date, and other specifics are provided in the attached solicitation.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| N6426725R0001_SAM_20241017.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Source: http://assist.dla.mil -- Downloaded: 2024-09-13T18:26Z Check the source to verify that this is the current version before use.
DATA ITEM DESCRIPTION
Title: CYBERSECURITY VULNERABILITY REPORT
Number: DI-MGMT-82191 Approval Date: 20180322
AMSC Number: N9908 Limitation: N/A
DTIC Applicable: N/A GIDEP Applicable: No
Preparing Activity: SH Project Number: MGMT-2018-021
Applicable Forms: N/A
Use/Relationship: The Cybersecurity Vulnerability Report provides information on the current state of the network security infrastructure. It provides information needed to understand and improve the security posture.
This data item description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirement as delineated in the contract.
Requirements:
Format. The Cybersecurity Vulnerability Report shall be in contractor’s format. 1.
Content. The Cybersecurity Vulnerability Report shall include the following: 2.
a) Unmitigated CAT I (High and Critical) – Total
b) Unmitigated CAT I (High and Critical) – Over 30 days
c) Unmitigated CAT II (Medium) – Total
d) Unmitigated CAT II (Medium) – Over 180 days
e) Raw CAT III (Low) – Total
f) Explanation of why remediation was not applied to 100 percent of affected assets for all outstanding open remediation actions.
g) Monthly Asset Discovery Results w/delta
h) All findings open longer than 30 days will be carried over to quarterly
Information Security POAM.
2.1. POC. Identify Office/Organization responsible for resolving vulnerability.
2.2. Additional Resources Required
a) Purchase requirements
b) Additional or shift of manpower
End of DI-MGMT-82191
Source: http://assist.dla.mil -- Downloaded: 2024-09-13T18:25Z
File details come from the government source that posted it. Updated .