PAISC_Q A.pdf
PDF 539 KB Posted
- Attached to
- Paying Agent-related Information Security Consultant (PAISC) Federal contract opportunity
- Solicitation number
- PBGC01-RP-12-0060
- Issued by
- Pension Benefit Guaranty Corporation
About this file
Questions and Answers
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| PAISC_Attachment A1.pdf | ||
| PAISC_Attachment C.pdf | ||
| FormSF30.pdf | ||
| PAISC_Attachment B.pdf | ||
| PAISC_Attachment A2.pdf | ||
| Request for Proposal.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAISC-Questions-and-answers.docx 1
Paying Agent-related Information Security Consulting (PAISC) Contract
PBGC01-RP-12-0025 Questions and answers
Contents
Q & A #1: Questions 1 – 43 (posted ~7/16/2012)
Q & A #1: Questions 1 – 43 (posted ~7/16/2012)
1. Is there an incumbent, and is this a continuation of a work in process? If so, could you please provide the name of the incumbent and contract number? Also, how many FTE positions are provided by the incumbent and whether that resulted in appropriate levels of support?
Information security consulting services related to the Primary Paying Agent are currently provided by a subcontractor to the incumbent Paying Agent, State Street Corporation. The subcontractor provides four employees (two full time and two part time). This level of support has been appropriate in the past. This contract ends 9/30/2012 and its replacement (for paying agent services) is the subject of PA service RFP (PBGC01-RP-12-0006). PBGC has decided to obtain the related information security consulting services via a separate contract vehicle for
FY13 and beyond (PBGC01-RP-12-0060).
2. If there is no incumbent, do you have an estimate on the number of FTE positions to provide appropriate levels of support?
See #1.
3. Please provide the total number of in-scope infrastructure components – i.e. workstations, network devices, IDS/IPS, etc. for the primary paying agent site along with their platforms (i.e.
operating system name – UNIX, Windows, AS/400, etc., database name – MS SQL, Oracle, MySQL, etc., firewall name – Cisco, Juniper, CheckPoint, etc.).
See the RFP, section C, item 1.3.1 regarding estimated server count, locations, etc. See PBGC01-
RP-01-0006, performance work statement, section C (available on Fedbiz Opps) to gain additional insights on the nature and magnitude of services provided by the Paying Agent including estimated volumes of payment-related transactions. Paying Agent Services RFP
(PBGC01-RP-12-0006) award is anticipated before 10/1/2012.
4. Please provide the total number of in-scope infrastructure components – i.e. workstations, network devices, IDS/IPS, etc. for the 12 different locations within the boundary of the paying agent program along with their platforms (i.e. operating system name – UNIX, Windows, AS/400, etc., database name – MS SQL, Oracle, MySQL, etc., firewall name – Cisco, Juniper, CheckPoint, etc.).
PAISC-Questions-and-answers.docx 2
See #3.
5. Please provide all systems of record that will be impacted by this requirement and indicate whether a Privacy Impact Assessment has been conducted on these system(s) or if this will be a new requirement.
See #1 and #16, but PBGC’s existing Paying Agent contract is aligned with PBGC’s SORN PBGC-6 at http://www.pbgc.gov/prac/pg/other/guidance/privacy-act-notices.html .
6. Section 1.3.2 references “Attachment A”, “Attachment B”, and “Attachment C”. Further, Section J indicates that the vendor needs to request the same from the POCs. Please accept this as our formal request for all the 3 stated attachments?
These will be made available via FedBizOpps.
7. Will the scope include evaluation of PBGC paying agents information Security practices?
Yes, the Security Assessment & Authorization process certainly requires that one evaluate the
Info Sec practices of the entity.
8. Will the scope include evaluation of PBGC sub-contractors information Security practices?
Yes, to the extent that any sub-contractors hired by the Paying Agent have access to PBGC data.
9. When was the PBGC’s Operations Manual updated?
The PBGC BAPD Operations Manual is updated, generally speaking, three times a year. The last update was published April 30, 2012.
10. When was the PBGC‘s Policy Manual Updated?
The PBGC Operating Policy Manual is updated, generally speaking, three times a year. The last update was published April 30, 2012.
11. Section 1.4.2; “The contractor will serve as project manager over the Security Assessment and
Authorization (SA&A) process and complete system security tests and evaluations.”
a. Will the contractor be managing the PBGC project or is the contractor required to perform the tasks also?
The contractor is expected to both manage the project and perform the tasks with support of staff from PBGC (especially the PBGC Information Owner (IO) and Information
Systems Security Officer (ISSO)) and the paying agent. See for example, SOO, sections
1.4.3 – 1.4.4 for specific examples of activities required of the contractor that go beyond project management: subject matter expert, gather artifacts, respond to finds, maintain records, meeting minutes, etc.
b. If the contractor is managing the PBGC project who is performing the SA&A process?
See #11A.
http://www.pbgc.gov/prac/pg/other/guidance/privacy-act-notices.html
PAISC-Questions-and-answers.docx 3
c. If third party is performing SA&A what authority does the contactor have over them to ensure quality of deliverables and timely delivery of reports?
See #11A.
12. When was the last PBGC security assessment performed?
See #1, but for PBGC’s existing Paying Agent contract PBGC’s security assessment is performed at least annually, last updated June 2012.
13. When where the PBGC security controls evaluated?
See #1, but for PBGC’s existing Paying Agent contract security controls are evaluated on an on-going basis thru a continuous monitoring program.
14. System Categorization:
a. When was PBGC system categorization performed?
See #1, but for PBGC’s existing Paying Agent contract PBGC’s system categorization is performed at least annually, last updated May 2012.
b. When was PBGC system categorization information updated?
See #14A.
c. Have there been any changes in the PBGC environment since then?
No.
15. System Security Plan:
a. When was the PBGC System Security Plan developed?
See #1, but for PBGC’s existing Paying Agent contract PBGC’s system security plan is reviewed and updated at least annually. It was last updated June 2012.
b. When was the PBGC System Security Plan updated?
See #15A.
16. Privacy Impact Assessment:
a. When was the PBGC Privacy Impact Assessment performed?
See #1, but for PBGC’s existing Paying Agent contract PBGC’s privacy impact assessment is reviewed and updated at least annually. It was last updated 2011.
b. Have there been any changes in the PBGC environment since then?
PAISC-Questions-and-answers.docx 4
17. Business Impact Assessment:
a. When was the PBGC Business Impact Assessment Performed?
These are managed on an on-going basis as part of the continuous monitoring program.
As new risks are identified, BIAs are conducted as needed.
b. When was the PBGC Business Impact Assessment Plan updated?
See #17A.
See #17A.
18. Plan of Action and Milestones (POA&M):
a. When was the PBGC POA&M developed?
See #1, but for PBGC’s existing Paying Agent contract PBGC manages their POA&Ms on an on-going, bi-weekly basis as part of the continuous monitoring program.
b. When was the PBGC POA&M updated?
See #18A.
See #18A.
19. How many Interconnection Security Agreements does PBGC have in place?
The PBGC has many Interconnection Security Agreements (ISA) only one of which is within the scope of this solicitation.
20. Does PBGC have an active Information Security Management System (ISMS) Program?
It’s not clear what you mean by ISMS Program. PBGC certainly does have a policies and procedures governing Information Security.
21. Does PBGC have an active Information Security Continuous Monitoring (ISCM) Program?
Yes.
22. What tools or technologies does PBGC use at present for ISCM?
See #1. PBGC’s incumbent Paying Agent, State Street, uses a third party vendor to provide the
PBGC with tools and technologies to support the ISCM.
23. What tools or technologies does PBGC use at present for monitoring security incidents?
See #22.
24. Is this a new requirement or Incumbent is providing the similar services, if Yes, than who is the incumbent and what was the awarded amount of last contract and period of performance?
PAISC-Questions-and-answers.docx 5
25. Does government has level of effort estimated, that is number of resources?
26. Please confirm that this is for the application related security only, not infrastructure or hardware related.
The security program will include the paying agent application(s), along with the infrastructure, hardware, and personal that will be used by the paying agent to support the application(s) which will contain PBGC data.
27. Section 1.4.3 discusses developing a continuous monitoring plan that includes automated workflows. What internal tools do you have in use to support automated workflows?
SharePoint? Remedy based system?
PBGC is currently in the process of implementing SharePoint. It is also thought that the vendor may have integrated automated workflows within the context of requirement 1.4.5 (p. 15, Automated compliance management and continuous monitoring support).
28. Does the PA system now maintain their POA&M in an automated form, i.e., a POA&M database?
29. Will the ISMS software reside on your server or are we to purchase the hardware? If your server, what are the specifications? What other personnel besides the Security Consultant contractor do you anticipate using the ISMS software?
It is expected that the ISMS will be a web hosted application which PBGC will have access to.
PBGC anticipates that the following key PBGC personnel would need access to the ISMS software: Information Owner (IO), Information System Security Officer (ISSO), and Contracting
Officer Representative (COR).
30. Please confirm that there is no SSP, PMP, QMP, Communications Plan, Staffing Plan, and Risk
Management Plan currently written. Can we assume that these will be developed from scratch under the work covered by the RFP?
See #1. PBGC’s incumbent Paying Agent, State Street has as part of their current contract developed and documented all of these.
31. Has there been a prior Security Authorization (previously referred to as C&A) for the PA system?
See #1. PBGC’s incumbent Paying Agent, State Street has completed an C&A.
32. Will travel be required to support the contingency plan exercise?
PAISC-Questions-and-answers.docx 6
See SOO, section 1.4.3, paragraph 5, that references “site inspections” and section 1.3.1 for estimated number of locations.
33. What type of access logs are maintained currently for the PA system?
34. What kind of activity logs are maintained currently for the PA system?
35. Are PA user account management activities logged?
36. What vulnerability scanning tools are currently being used to assess vulnerabilities in the PA system?
37. Please provide copies of all documents listed in section 1.3.2.1.
See #6.
38. Does the organization have a Continuous Monitoring program currently in place?
See #21.
39. Has the organization used any automated tools to support the security program in the past such as FISMA Trusted Agent, XaCta, or PureFISMA?
Yes, the current Paying Agent, State Street provides a propriety software application to the
PBGC.
40. How many systems and type make up the current environment? How many major applications, minor applications, and general support systems and where are they located?
See #3.
41. Is there an existing framework for a tool repository? What are the requirements and preferences for the tool type, OS, and whether it should be client server or web based?
See #29. The PBGC has no further requirements and preferences for the tool, beyond what is stated in the SOO.
42. Do you expect the contractor to build the ISMS using an existing environment and platform?
See #29.
43. Do you expect the vendor to come in with a fully licensed tool and the price for the cost of the tool to be included in the quote for this RFP?
File details come from the government source that posted it. Updated .