FormSF30.pdf
PDF 10 MB Posted
- Attached to
- Paying Agent-related Information Security Consultant (PAISC) Federal contract opportunity
- Solicitation number
- PBGC01-RP-12-0060
- Issued by
- Pension Benefit Guaranty Corporation
About this file
Amendment 01
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| PAISC_Attachment A1.pdf | ||
| PAISC_Attachment C.pdf | ||
| PAISC_Q A.pdf | ||
| PAISC_Attachment B.pdf | ||
| PAISC_Attachment A2.pdf | ||
| Request for Proposal.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
NSN 7540-01-152-8070 STANDARD FORM 30. (Rev. 10-83) Previous Edition unusable Prescribed by GSA FAR (48 CFR) 53.243
Page of Pages AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT 1. Contract ID Code
2. AMENDMENT MODIFICATION NO. 3. EFFECTIVE DATE 4. REQUISITION/PURCHASE REQ. NO. 5. PROJECT NO. (if applicable)
6. ISSUED BY CODE 7. ADMINISTERED BY (If other than item 6) CODE
(x) 9A. AMENDMENT OF SOLICITATION NO.
9B. DATED (SEE ITEM 11)
10A. MODIFICATION OF CONTRACT/ORDER NO.
8. NAME AND ADDRESS OF CONTRACTOR (NO., Street, Country, State and ZIP Code)
CODE FACILITY CODE
10B. DATED (SEE ITEM 13)
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
The above numbered solicitation is amended as set forth in item 14. The hour and date specified for receipt of offers is extended, is not extended.
Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods:
(a) By completing items 8 and 15, and returning ______ copies of amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted;
or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OR OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment your desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.
12. ACCOUNTING AND APPROPRIATION DATA (If required)
13. THIS ITEM ONLY APPLIES TO MODIFICATION OF CONTRACTS/ORDERS. IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.
Check One
A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE
CONTRACT ORDER NO. IN ITEM 10A.
B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).
C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
D. OTHER (Specify type of modification and authority)
E. IMPORTANT: Contractor is not, is required to sign this document and return _______ copies to the issuing office.
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible)
Except as provided herein, all terms and conditions of the document referenced in item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.
15A. NAME AND TITLE OF SIGNER (Type or print)
16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)
15B. CONTRACTOR/OFFEROR 16B. UNITED STATES OF AMERICA
(Signature of person authorized to sign)
15C. DATE SIGNED
(Signature of Contracting Officer)
16C. DATE SIGNED
Table of Contents
PAGE 2 OF 16 PBGC01-RP-12-0025/01
SECTION B SUPPLIES OR SERVICES AND PRICES/COSTS
SECTION C DESCRIPTION/SPECIFICATIONS/WORK STATEMENT
PAGE 3 OF 16 PBGC01-RP-12-0025/01
SECTION B
SUPPLIES OR SERVICES AND PRICES/COSTS
B. 1
Paying Agent-related Information Security Consultant (PAISC) Contract
PBGC Solicitation Number PBGC01-RP-12-0025
B.1 SUPPLIES OR SERVICES AND PRICES/COSTS
1.1 DESCRIPTION OF SERVICES
The Contractor shall provide the necessary services as described in the Performance Work Statement, Section C. The resulting contract under this Solicitation will be Performance- Based. This is a Firm Fixed Price procurement.
1.2 PRICING SCHEDULE
Base Year
ITEM SUPPLIES/SERVICES QTY UNIT UNIT
PRICE
TOTAL
AMOUNT
CLIN 0001 The Contractor shall perform all services required as proposed in the Performance Work Statement.
12 Lump Sum
CLIN 0002 Travel 12 NTE $25,000
Option Year One
PRICE
TOTAL
AMOUNT
CLIN 1001 The Contractor shall perform all
CLIN 1002 Travel 12 NTE $25,000
Option Year Two
PRICE
TOTAL
AMOUNT
CLIN 2001 The Contractor shall perform all
CLIN 2002 Travel 12 NTE $25,000
Option Year Three
PRICE
TOTAL
AMOUNT
CLIN 3001 The Contractor shall perform all
CLIN 3002 Travel 12 NTE $25,000
PAGE 4 OF 16 PBGC01-RP-12-0025/01
Paying Agent-related Information Security Consultant (PAISC) Contract
PBGC Solicitation Number PBGC01-RP-12-0025
Option Year Four
PRICE
TOTAL
AMOUNT
CLIN 4001 The Contractor shall perform all
CLIN 4002 Travel 12 NTE $25,000
B.2 PBGC-44-001 OTHER DIRECT COSTS (MAY 2012)
The contractor shall be reimbursed for the actual cost of other direct cost determined to be allowable in accordance with Part 31 of the Federal Acquisition Regulation and authorized by the Contracting Officer or his designee prior to the contractor incurring the charge.
PAGE 5 OF 16 PBGC01-RP-12-0025/01
SECTION C
DESCRIPTION/SPECIFICATIONS/WORK STATEMENT
C. 1
Paying Agentrelated Information Security Consultant (PAISC) Contract PBGC Solicitation Number PBGC01RP120025
Section C
1.3 Scope
This section of the statement of objectives provides an explanation of the scope of this contract.
The information is provided in three areas: (1) with regard to the information systems and business processes that will be associated with the work the contractor will be responsible for, (2) PBGC’s Directives, Memorandums, and other publications that the contractor will need to comply with, and (3) Federal mandates and laws that the contractor will need to adhere to within the scope of the work they will complete to satisfy this contract.
1.3.1 Paying Agent (PA) Program Systems and Business Processes
Systems included in the PA program are those required for the payment of pension benefit to our participants and include transfer of payment files between PBGC and its primary paying agent. Furthermore, this program includes the system interaction to allow participants to see copies of their paper checks and images of their tax forms.
Characteristics of the paying agent program include the following key parameter approximations so that offers have a sense of size, breadth, and complexity of the paying agent program:
• Paying agent program is a third party web hosted system
• 50 servers within the boundary of the primary paying agent site
• 50 employees at the paying agent have access to PBGC information and/or support PBGC processes
• 500 PBGC employees use the paying agent system in some capacity
• 12 total different locations within the boundary of the paying agent program all located within the continental United States o Two locations for PBGC headquarters and backup site o Two locations for Primary paying agent and backup site o 8 locations for primary paying agent subcontractors and backup sites
Business processes and procedures included in the Paying Agent Program are those found in the PBGC’s Operations Manual and Policy Manual which directly relate to the payment of pension benefits to participants.
1.3.2 PBGC Memoranda, Directives, Standards, and other publications
PAGE 6 OF 16 PBGC01-RP-12-0025/01
PBGC Solicitation Number PBGC01RP120025
Section C
Below are listed those PBGC’s authoritative information which govern this contract. The contractor will be responsible for staying abreast of and implement new or modified directives, policies, standards, and procedures published during the life of this contract.
1.3.2.1 Enterprise Information Security Office (EISO) directives, programs, and policies (see Attachment A, for copies of these documents)
• PBGC Directive IM 0502: PBGC Information Security Policy
• SEPRO0101: OIT Information Systems Registration Process
• SEPRO0201: PBGC Plan of Action and Milestones Process
• SEPRO0301: PBGC User & Account Access Recertification Process
• SESTD0101: PBGC Personnel Security Standard
• SESTD0102: PBGC External Information Systems and Services Standard
• SESTD0103: PBGC Public Information Security Standard
• SESTD0104: PBGC System Privilege Standard
• SESTD0105: PBGC Boundary Security Standard
• SESTD0106: PBGC Transmission Integrity and Confidentially Standard
• SESTD0107: PBGC Cryptography Standard
• SESTD0108: PBGC Domain Name Services Security Standard
• SESTD0109: PBGC Information Output Handling and Retention Standard
• SESTD0110: PBGC Rules of Behavior Standard
• SESTD0111: PBGC System Security Plan Standard
• SESTD0112: PBGC Privacy Impact Assessment
• SESTD0113: PBGC Security Categorization Standard
• SESTD0114: PBGC Risk Assessment Standard
• SESTD0115: PBGC Vulnerability Scanning Standard
• SESTD0116: PBGC Plan of Action and Milestone Standard
• SESTD0117: PBGC Life Cycle Security Standard
• SESTD0118: PBGC Security Impact Analysis Standard
• SESTD0119: PBGC Access Restrictions for Change Standard
• SESTD0120: PBGC Physical & Environmental Security Standard
• SESTD0121: PBGC Security Incident Handling Standard
• SESTD0122: PBGC Security Audit Standard
• SESTD0123: PBGC Information System Monitoring Standard
• SESTD0124: PBGC Maintenance Security Standard
• SESTD0125: PBGC Physical Access Standard
• SESTD0126: PBGC Information System Connections Standard
PAGE 7 OF 16 PBGC01-RP-12-0025/01
PBGC Solicitation Number PBGC01RP120025
Section C
• SESTD0127: PBGC Identification and Authentication Standard
• SESTD0128: PBGC Media Security Standard
• SESTD0129: PBGC Security Training and Testing Standard
• SESTD0130: PBGC System Protection Standard
• SESTD0131: PBGC UserInstalled Software Standard
• SESTD0132: PBGC Access Control Standard
• SESTD0133: PBGC Voice over Intranet Protocol Standard
• SEGDE0101: Security Authorization Guide
• SEPRC0101: PBGC Security Awareness and Training Procedures
• SEPRC0101: Security Incident Response Procedures
1.3.2.2 PBGC Information Technology System Life Cycle Methodology (see Attachment B, for copies of these documents)
• PBGC Directive IM0507, PBGC’s Information Technology Solutions Life Cycle Methodology
• PMPRO0101: IT Solutions Life Cycle Management (ITSLCM) Framework Narrative
• PMSTD0101: PBGC OIT System Documentation Standard
• PMSTD0102: PBGC OIT Design & COTS Configuration Document
Standard
• PMSTD0103: PBGC OIT Requirements Document Standard
• PMSTD0104: Implementation and Training Plan Standard
• PMSTD0105: Lessons Learned Document Standard
• PMGDE0101: IT Solutions Life Cycle Management (ITSLCM) v1.1
Framework Narrative
• PMREF0101: ITSLCM v1.1 Views
1.3.2.3 Records management (see Attachment C, for copies of these documents)
• PBGC Records Management Program Guidance [Interim] (February 2012)
• PBGC Records Management Procedures Manual (version 1.0)
1.3.2.4 Privacy information and security (see Attachment C, for copies of these documents)
• PBGC Directive IM 0509, Privacy Program
• PBGC Directive IM 1003, Protecting Sensitive Information
• PBGC Directive PM 0501, PBGC Entrance on Duty and Separation
Procedures for Federal and Contract Employees
• PBGC Directive PM 0506, Personnel Security and Suitability Program
PAGE 8 OF 16 PBGC01-RP-12-0025/01
PBGC Solicitation Number PBGC01RP120025
Section C
1.3.3 U.S. Federal laws and regulations, including but not limited to, the following Below are listed those Federal laws, regulations, and other publications which are highly relevant to this contract. The contractor will be responsible for staying abreast of and implement of any new or modified publications issued during the life of this contract.
1.3.3.1 The Office of Management and Budget (OMB) circulars, memorandums, and publications
• OMB Circular A11, Part 7, Planning, Budgeting, Acquisition, and Management of Capital Assets, updated August, 2009, and the Capital Planning Guide, issued 2006
• OMB Circular A123, Management’s Responsibility for Internal Control
• OMB Circular A127, Financial Management Systems
• OMB Circular A130, Management of Federal Information Resources, including Appendix III, Security of Federal Automated Information Resources
• OMB Memorandum 0322, OMB Guidance for Implementing the Privacy
Provisions of the EGovernment Act of 2002
• OMB Memorandum 0616, Protection of Sensitive Agency Information
• OMB Memorandum 0716, Safeguarding Against and Responding to the
Breach of Personally Identifiable Information
1.3.3.2 U.S. Department of Commerce’s National Institute of Standards and
Technology (NIST) publications including relevant Federal Information Processing Standards (FIPS)
• NIST SP 80018, Guide for Developing Security Plans for Federal Information Systems
• NIST SP 80030 Risk Management Guide for Information Technology Systems
• NIST SP 80034 Contingency Planning Guide for Information Technology Systems
• NIST SP 80037 Guide for Applying the Risk Management Framework to Federal Information Systems
• NIST SP 80053 Recommended Security Controls for Federal Information Systems and Organizations
• NIST SP 80053A – Guide for Assessing the Security Controls in Federal Information Systems and Organizations
PAGE 9 OF 16 PBGC01-RP-12-0025/01
PBGC Solicitation Number PBGC01RP120025
Section C
• NIST SP 80060 Volume I and II Guide for Mapping Types of Information and Information Systems to Security Categories
• NIST SP 800122 Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)
• NIST SP 800137 – Information Security Continuous Monitoring for Federal Information Systems and Organizations
• FIPS 1402, Security Requirements for Cryptographic Modules
• FIPS 199, Standards for Security Categorization of Federal Information and
Information Systems
• FIPS 200, Minimum Security Requirements for Federal Information and
Information Systems
• FIPS 2011, Personal Identity Verification of Federal Employees and
Contractors
1.3.3.3 Other relevant U.S. Government information (publications, directives, acts, orders, etc.)
• 5 U.S.C., Privacy Act of 1974 PL 93579, as amended
• 5 U.S.C., Privacy Act of 1974 PL 552a, as amended
• 18 U.S.C., Computer Fraud and Abuse Act
• Computer Security Act of 1987, Public Law No. 100235
• Information Technology Management Reform Act of 1996
• Executive Order 13103, “Computer Software Piracy”
• Presidential Decision Directive 63 of May 22, 1998, Critical Infrastructure
Protection
• Title III of the EGovernment Act of 2002 – Federal Information Security
Management Act of 2002 (FISMA), Public Law No. 107347
• Government Paperwork Elimination Act of 1998 (GPEA), PL 105277
• The Freedom of Information Act, PL 93502
• The Federal Managers' Financial Integrity Act of 1982 (FMFIA), PL 97255
• The Rehabilitation Act of 1973, as amended
• Government Accountability Office, Investment Management Executive
Guide, GAO04394G
• Federal Risk and Authorization Management Program (FedRAMP)
PAGE 10 OF 16 PBGC01-RP-12-0025/01
PBGC Solicitation Number PBGC01RP120025
Section C
1.4 Requirements
Below are PBGC’s requirements of the contractor with regard to the services and deliverables for this contract. All of the activities and deliverables listed below will be completed with adherence to sections 1.3.2 and 1.3.3 of this statement of objectives.
Reference section 1.5 Deliverables for a detailed listing of all the required documents for which the contractor will be required to submit.
1.4.1 A holistic approach to Risk Management
The contractor will develop a Risk Management Program at the system information level (tier 3) based upon the Risk Management Framework (RMF) as outlined in the current version of NIST SP 80037. This Risk Management Program will be based upon a methodology that will ensure program compliance and use of PBGC’s EISO and/or industry best practices to support the most effective and efficient use of resources. It is expected that the Risk Management Program for this tier 3 effort will tie to and directly support PBGC’s Enterprise Risk Management Program. Furthermore, the Risk Management program will integrate with system development life cycle (specifically PBGC’s ITSLCM, see section 1.3.2.2).
1.4.2 Security Assessment and Authorization (SA&A)
The contractor will serve as project manager over the Security Assessment and Authorization (SA&A) process and complete system security tests and evaluations. This will include review of the PA’s self assessment of security controls. The contractor will conduct comprehensive evaluations of the security controls and other safeguards to determine and document the extent to which the design and implementation meet NIST and PBGC’s EISO requirements.
The contractor will support security authorization of the PA’s program systems by:
reviewing and evaluating system categorization; documenting and maintaining the PA program’s System Security Plan (SSP) and related control matrix; and developing Privacy Impact Assessment (PIA), Interconnection Security Agreement (ISA), and other PBGC specified EISO required documentation. The contractor will develop project schedules and serve as project manager for those activities needed for ongoing authorization as outlined in NIST SP 80037 process and PBGC’s EISO standards.
PAGE 11 OF 16 PBGC01-RP-12-0025/01
PBGC Solicitation Number PBGC01RP120025
Section C
The contractor will be responsible for responding to emergent information system security authorization and security requirements from U.S. Federal Government and
PBGC.
1.4.3 Information Security Continuous Monitoring (ISCM) Program
The Contractor will centrally manage the tier three level Information Security Continuous Monitoring (ISCM) program1 so that all necessary activities as required by NIST SP 800137 are planned and managed in a proactive coordinated manner.
The contractor will support the establishment of the ISCM Strategy by: planning, selecting the security controls with associated tasks, which “provides security status information for all tiers and realtime updates for ongoing system authorization decisions” (NIST SP 800137, p. 20). The contractor will perform risk assessments regarding changes to the PA system’s environment or impact due to PBGC’s changing environment, including Business Impact/Risk Assessment (BIA/RA) recommendations based on both security and business considerations, in coordination with PBGC’s EISO and the PA.
The contractor will then establish the ISCM Program by: developing a continuous monitoring plan that includes automated workflows to support efficient and effective process, and create a program schedule. The contractor will identify metrics for each control, establish monitoring and assessment frequencies, and develop the ISCM architecture that will be used to support information collection and delivery.
Then the contractor will implement the ISCM Program by: facilitating meetings with security team members from PBGC and its contractors; and develop, coordinate, support and test all NIST SP 80053 controls.
Next the contractor will be responsible for analyzing data and reporting findings. This will require the contractor to collect securityrelated information and metrics and then assess the collected data. The contractor will perform data collection efforts (e.g.
interviews, site inspections, scanning, and other test activities) for control implementation by: serving as project manager for these type of efforts; supporting
1 See NIST SP 800137 (rev. 1), Chapter 3, which outlines the process for developing and implementing an ISCM program.
PAGE 12 OF 16 PBGC01-RP-12-0025/01
PBGC Solicitation Number PBGC01RP120025
Section C
PBGC as subject matter expert; along with being responsible for gathering necessary artifacts from the PA and other sources.
The contractor will respond to findings. This step of the program will require the contractor to prepare appropriate reports and deliverables required to address information security finds. The contractor will manage the Plan of Action and Milestones (POA&M) process by: leading program meetings; maintaining records of the remediation and verification of activities; maintaining POA&M prioritization, tracking, and alerts; serving as the subject matter expert on mitigation strategies to ensure resolutions are inline with PBGC’s EISO requirements; and assisting in the completion of POA&M remediation efforts.
The last, but by no means least step in the ISCM program will require the contractor to review and update the monitoring program and strategy on an ongoing basis. The contractor will make recommendations and updates to the continuous monitoring plan based on the continually evolving environment and vulnerabilities. The contractor will also ensure the PA security program information and data (i.e., System Security Plan together with Risk Assessment Report, Security Assessment Report and POA&M) are current on an ongoing basis.
1.4.4 Facilitate and support audits, compliance reviews, and other information requests
The contractor will facilitate and support various audits and reviews as they relate to the PA systems by: helping to identify and map necessary artifacts to support auditors, facilitate compiling artifacts, provide auditors with access to needed program documentation (artifacts), coordinate and facilitate responses to questions, and serve as subject matter expert.
The contractor will facilitate and support IT system securityrelated information requests from internal and external sources, including, but not limited to, PBGC management, PBGC’s Enterprise Security Office (EISO), and the Office of Management and Budget
(OMB).
The contractor will support preparation of capital asset planning and business case summary with PA information security related information.
PAGE 13 OF 16 PBGC01-RP-12-0025/01
PBGC Solicitation Number PBGC01RP120025
Section C
1.4.5 Automate compliance management and continuous monitoring support
The contractor will provide an Information Security Management System (ISMS) for which security documents, reports, and artifacts can be maintained. This system must include the following features
• Centralized database that will store all compliance details and artifacts;
• Dashboard summarizing the overall security status of the system (e.g. number of controls implemented, planned, inherited, etc.);
• Built in NIST SP 80053 control information – Including definitions and controls levels for PA program, systems, and subsystems;
• Ability to link artifacts to those NIST SP 80053 controls for which it supports;
• Audit feature which logs all adds, deletes, and modifications for both documentation repository and user activity;
• Rolebased user access to include administrative, read/write, and read only access;
• Report generation capability to facilitate custom and adhoc reports as needed; and
• Flexibility in adjusting to the evolving changes in compliance regulations and standards by allowing for quick and easy updates to the NIST controls.
Furthermore, the contractor will be responsible for ensuring the ISMS operations and maintenance. This will include, but not be limited to
• System authorization and access management,
• Daily system operations and server,
• Ongoing upgrades,
• Security management and authorization to operate processing, and
• Integration of workflows and process updates based on PBGC defined processes.
1.4.6 Program management support
The contractor will be responsible for leading meetings which will include preparing agendas, facilitation of sessions, meeting minutes, and coordination of action items.
Notification to attendees along with arranging for facilities and other resources needed to support various meetings will also be required of the contractor.
As a program manager, the contractor’s responsibilities include planning, preparing program and project schedules, coordination of activities, maintaining project
PAGE 14 OF 16 PBGC01-RP-12-0025/01
PBGC Solicitation Number PBGC01RP120025
Section C documentation, and leading project team members in project tasks in support of reaching program goals. The program manager is expected to be proactive in identification of risk and when issues do materialize will implement agreed upon mitigating strategies to reduce program impact.
The contractor will also develop, review, and update the following key program management documents
• Program Management Plan – once developed reviewed at least annually
• Quality Assurance Plan – once developed reviewed at least annually
• Communications Plan once developed reviewed at least annually
• Staffing Plan – once developed reviewed at least annually
• Risk Management Plan – once developed reviewed at least quarterly
• Program Schedule – once developed reviewed at least monthly
The contractor will hold regular program status update meetings with the Contracting Officer’s Representative (COR). The contractor will provide monthly status reports on program activities and ensure that all program and project documentation is delivered as outlined in program schedule (see section 1.5, Deliverables for further details).
1.4.7 Other services in support of risk management program
Supports systemspecific contingency plans as it relates to both the PA and PBGC: will review and make recommendations; and coordinate, update and support exercises, as needed.
The contractor will provide information security guidance and technical expertise to Information System Owners (ISO), Information Owners (IO), Authorizing Official (AO), and others as defined by COR. The contractor will prepare security briefings and presentations to be used and presented by the IO, AO, and others as defined by COR.
The contractor may be asked to present program related information to PBGC management. The contractor will review and provide feedback on securityrelated policies, procedures, and templates as requested.
PAGE 15 OF 16 PBGC01-RP-12-0025/01
PBGC Solicitation Number PBGC01RP120025
Section C
1.5 Deliverables
The following is a list of the key deliverables for which the offeror will be responsible for as a part of the contract. These documents will be developed, maintained, and updated as outlined in the Program Management Plan & Program Schedule.
The vendor’s Quality Assurance Surveillance Plan (QASP) which is submitted as part of the proposal package will serve as a basis for the Service Level Agreement (SLA) which will be used to validate performance, of services and deliverables, in order to all the government to approve of payments. The SLA will be agreed upon with the first 30 days of the contract award and will be included in the contract by reference.
1.5.1 Risk Management Plan
1.5.2 Security Assessment and Authorization (SA&A) Documentation
Baseline report for each control & tailoring plan
System Registration Documentation
• Classification and Determination Memo
• Categorization (FIPS 199) Document
• Privacy Threshold Analysis (PTA)
• Privacy Impact Assessment (PIA)
System Security Plan (SSP) and related matrix
Interconnection Security Agreement (ISA)
Memorandums of Understanding (MOU), if required
Security Assessment Report (SAR)
System Authorization Boundary Document
1.5.3 Information Security Continuous Monitoring (ISCM) Program Documentation
ISCM Program Plan & project schedule
ISCM Risk Log
Attestation letters
PAGE 16 OF 16 PBGC01-RP-12-0025/01
PBGC Solicitation Number PBGC01RP120025
Section C
External Scan summary reports
Plan of Action and Milestones (POA&M) reports
Risk Acceptance reports/documents
Request for Closure (RFC) reports/documents
Business Impact/Risk Assessment (BIA/RA) reports
1.5.4 Information Security Management System (ISMS) Documentation
1.5.5 Other Documentation
Authorizing Official (AO) Management Updates & Presentations
Meeting Agendas, minutes, and reports for Program meetings
1.5.6 Program Management Documentation
Program Management Plan
Quality Assurance Plan
Communications Plan
Staffing Plan
Risk Management Plan
Program Schedule – to include a program activities calendar, task list, deliverables List, Contract Administration Reports – such as Monthly status reports, Quarterly status reports
Descript: The purpose of this amendment is to revise Section B, Section C, to incorporate the attachments referenced in Section J, and to incorporate the Questions and Answers into the solicitation.
All other terms and conditions remain unchanged.
| Descript1: |
| AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT: |
| IDCode: |
| pdfpage1: 1 |
| Pages: 16 |
| DocNo: 01 |
| EffDate: JUL 20, 2012 |
| ReqNo: RQ-35-13-000002 |
| ProjNo: |
| IssuedByCode: PD |
| IssuedBy: PENSION BENEFIT GUARANTY CORP |
PROCUREMENT DEPARTMENT
1200 K STREET NW
WASHINGTON DC 20005-4026
| AdminByCode: |
| AdminBy: See Block 6 |
| ContractorCode: |
| FacCode: |
| SolChg: Yes |
| AwdChg: Off |
| SolNo: PBGC01-RP-12-0025 |
| SolDate: JUL 20, 2012 |
| AwdNo: |
| AwdDate: |
| NoCopies: 1 |
| Amended: Yes |
| OffrExt: Off |
| OffrNoEx: No |
| ApprData: See Schedule |
| ChgeOrd: Off |
| ChgeOrder: |
| Modify: Off |
| B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).: |
| SuppAgre: Off |
| SuppAuth: |
| ModOthr: Off |
| OthrSpec: |
| NoReq: Off |
| Require: Off |
| Copies: |
| SignName: |
| SignTitl: |
| ContDate: |
| ContrOfficerInfo: |
| CODate: |
| Contractor Info: |
| ContractorPOC: |
| Contractor: |
| ModAmount: |
| Header: |
| 15B. CONTRACTOR/OFFEROR: |
| Footer1: |
| signature: |
File details come from the government source that posted it. Updated .