PAISC_Q A.pdf

PDF 539 KB Posted

Attached to
Paying Agent-related Information Security Consultant (PAISC) Federal contract opportunity
Solicitation number
PBGC01-RP-12-0060
Issued by
Pension Benefit Guaranty Corporation

About this file

Questions and Answers

View the file

Other files for this federal contract opportunity

Other files attached to Paying Agent-related Information Security Consultant (PAISC), newest first.
File Type Posted
PAISC_Attachment A1.pdf PDF
PAISC_Attachment C.pdf PDF
FormSF30.pdf PDF
PAISC_Attachment B.pdf PDF
PAISC_Attachment A2.pdf PDF
Request for Proposal.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAISC-Questions-and-answers.docx 1

Paying Agent-related Information Security Consulting (PAISC) Contract

PBGC01-RP-12-0025 Questions and answers

Contents

Q & A #1: Questions 1 – 43 (posted ~7/16/2012)

Q & A #1: Questions 1 – 43 (posted ~7/16/2012)

1. Is there an incumbent, and is this a continuation of a work in process? If so, could you please provide the name of the incumbent and contract number? Also, how many FTE positions are provided by the incumbent and whether that resulted in appropriate levels of support?

Information security consulting services related to the Primary Paying Agent are currently provided by a subcontractor to the incumbent Paying Agent, State Street Corporation. The subcontractor provides four employees (two full time and two part time). This level of support has been appropriate in the past. This contract ends 9/30/2012 and its replacement (for paying agent services) is the subject of PA service RFP (PBGC01-RP-12-0006). PBGC has decided to obtain the related information security consulting services via a separate contract vehicle for

FY13 and beyond (PBGC01-RP-12-0060).

2. If there is no incumbent, do you have an estimate on the number of FTE positions to provide appropriate levels of support?

See #1.

3. Please provide the total number of in-scope infrastructure components – i.e. workstations, network devices, IDS/IPS, etc. for the primary paying agent site along with their platforms (i.e.

operating system name – UNIX, Windows, AS/400, etc., database name – MS SQL, Oracle, MySQL, etc., firewall name – Cisco, Juniper, CheckPoint, etc.).

See the RFP, section C, item 1.3.1 regarding estimated server count, locations, etc. See PBGC01-

RP-01-0006, performance work statement, section C (available on Fedbiz Opps) to gain additional insights on the nature and magnitude of services provided by the Paying Agent including estimated volumes of payment-related transactions. Paying Agent Services RFP

(PBGC01-RP-12-0006) award is anticipated before 10/1/2012.

4. Please provide the total number of in-scope infrastructure components – i.e. workstations, network devices, IDS/IPS, etc. for the 12 different locations within the boundary of the paying agent program along with their platforms (i.e. operating system name – UNIX, Windows, AS/400, etc., database name – MS SQL, Oracle, MySQL, etc., firewall name – Cisco, Juniper, CheckPoint, etc.).

PAISC-Questions-and-answers.docx 2

See #3.

5. Please provide all systems of record that will be impacted by this requirement and indicate whether a Privacy Impact Assessment has been conducted on these system(s) or if this will be a new requirement.

See #1 and #16, but PBGC’s existing Paying Agent contract is aligned with PBGC’s SORN PBGC-6 at http://www.pbgc.gov/prac/pg/other/guidance/privacy-act-notices.html .

6. Section 1.3.2 references “Attachment A”, “Attachment B”, and “Attachment C”. Further, Section J indicates that the vendor needs to request the same from the POCs. Please accept this as our formal request for all the 3 stated attachments?

These will be made available via FedBizOpps.

7. Will the scope include evaluation of PBGC paying agents information Security practices?

Yes, the Security Assessment & Authorization process certainly requires that one evaluate the

Info Sec practices of the entity.

8. Will the scope include evaluation of PBGC sub-contractors information Security practices?

Yes, to the extent that any sub-contractors hired by the Paying Agent have access to PBGC data.

9. When was the PBGC’s Operations Manual updated?

The PBGC BAPD Operations Manual is updated, generally speaking, three times a year. The last update was published April 30, 2012.

10. When was the PBGC‘s Policy Manual Updated?

The PBGC Operating Policy Manual is updated, generally speaking, three times a year. The last update was published April 30, 2012.

11. Section 1.4.2; “The contractor will serve as project manager over the Security Assessment and

Authorization (SA&A) process and complete system security tests and evaluations.”

a. Will the contractor be managing the PBGC project or is the contractor required to perform the tasks also?

The contractor is expected to both manage the project and perform the tasks with support of staff from PBGC (especially the PBGC Information Owner (IO) and Information

Systems Security Officer (ISSO)) and the paying agent. See for example, SOO, sections

1.4.3 – 1.4.4 for specific examples of activities required of the contractor that go beyond project management: subject matter expert, gather artifacts, respond to finds, maintain records, meeting minutes, etc.

b. If the contractor is managing the PBGC project who is performing the SA&A process?

See #11A.

http://www.pbgc.gov/prac/pg/other/guidance/privacy-act-notices.html

PAISC-Questions-and-answers.docx 3

c. If third party is performing SA&A what authority does the contactor have over them to ensure quality of deliverables and timely delivery of reports?

See #11A.

12. When was the last PBGC security assessment performed?

See #1, but for PBGC’s existing Paying Agent contract PBGC’s security assessment is performed at least annually, last updated June 2012.

13. When where the PBGC security controls evaluated?

See #1, but for PBGC’s existing Paying Agent contract security controls are evaluated on an on-going basis thru a continuous monitoring program.

14. System Categorization:

a. When was PBGC system categorization performed?

See #1, but for PBGC’s existing Paying Agent contract PBGC’s system categorization is performed at least annually, last updated May 2012.

b. When was PBGC system categorization information updated?

See #14A.

c. Have there been any changes in the PBGC environment since then?

No.

15. System Security Plan:

a. When was the PBGC System Security Plan developed?

See #1, but for PBGC’s existing Paying Agent contract PBGC’s system security plan is reviewed and updated at least annually. It was last updated June 2012.

b. When was the PBGC System Security Plan updated?

See #15A.

16. Privacy Impact Assessment:

a. When was the PBGC Privacy Impact Assessment performed?

See #1, but for PBGC’s existing Paying Agent contract PBGC’s privacy impact assessment is reviewed and updated at least annually. It was last updated 2011.

b. Have there been any changes in the PBGC environment since then?

PAISC-Questions-and-answers.docx 4

17. Business Impact Assessment:

a. When was the PBGC Business Impact Assessment Performed?

These are managed on an on-going basis as part of the continuous monitoring program.

As new risks are identified, BIAs are conducted as needed.

b. When was the PBGC Business Impact Assessment Plan updated?

See #17A.

See #17A.

18. Plan of Action and Milestones (POA&M):

a. When was the PBGC POA&M developed?

See #1, but for PBGC’s existing Paying Agent contract PBGC manages their POA&Ms on an on-going, bi-weekly basis as part of the continuous monitoring program.

b. When was the PBGC POA&M updated?

See #18A.

See #18A.

19. How many Interconnection Security Agreements does PBGC have in place?

The PBGC has many Interconnection Security Agreements (ISA) only one of which is within the scope of this solicitation.

20. Does PBGC have an active Information Security Management System (ISMS) Program?

It’s not clear what you mean by ISMS Program. PBGC certainly does have a policies and procedures governing Information Security.

21. Does PBGC have an active Information Security Continuous Monitoring (ISCM) Program?

Yes.

22. What tools or technologies does PBGC use at present for ISCM?

See #1. PBGC’s incumbent Paying Agent, State Street, uses a third party vendor to provide the

PBGC with tools and technologies to support the ISCM.

23. What tools or technologies does PBGC use at present for monitoring security incidents?

See #22.

24. Is this a new requirement or Incumbent is providing the similar services, if Yes, than who is the incumbent and what was the awarded amount of last contract and period of performance?

PAISC-Questions-and-answers.docx 5

25. Does government has level of effort estimated, that is number of resources?

26. Please confirm that this is for the application related security only, not infrastructure or hardware related.

The security program will include the paying agent application(s), along with the infrastructure, hardware, and personal that will be used by the paying agent to support the application(s) which will contain PBGC data.

27. Section 1.4.3 discusses developing a continuous monitoring plan that includes automated workflows. What internal tools do you have in use to support automated workflows?

SharePoint? Remedy based system?

PBGC is currently in the process of implementing SharePoint. It is also thought that the vendor may have integrated automated workflows within the context of requirement 1.4.5 (p. 15, Automated compliance management and continuous monitoring support).

28. Does the PA system now maintain their POA&M in an automated form, i.e., a POA&M database?

29. Will the ISMS software reside on your server or are we to purchase the hardware? If your server, what are the specifications? What other personnel besides the Security Consultant contractor do you anticipate using the ISMS software?

It is expected that the ISMS will be a web hosted application which PBGC will have access to.

PBGC anticipates that the following key PBGC personnel would need access to the ISMS software: Information Owner (IO), Information System Security Officer (ISSO), and Contracting

Officer Representative (COR).

30. Please confirm that there is no SSP, PMP, QMP, Communications Plan, Staffing Plan, and Risk

Management Plan currently written. Can we assume that these will be developed from scratch under the work covered by the RFP?

See #1. PBGC’s incumbent Paying Agent, State Street has as part of their current contract developed and documented all of these.

31. Has there been a prior Security Authorization (previously referred to as C&A) for the PA system?

See #1. PBGC’s incumbent Paying Agent, State Street has completed an C&A.

32. Will travel be required to support the contingency plan exercise?

PAISC-Questions-and-answers.docx 6

See SOO, section 1.4.3, paragraph 5, that references “site inspections” and section 1.3.1 for estimated number of locations.

33. What type of access logs are maintained currently for the PA system?

34. What kind of activity logs are maintained currently for the PA system?

35. Are PA user account management activities logged?

36. What vulnerability scanning tools are currently being used to assess vulnerabilities in the PA system?

37. Please provide copies of all documents listed in section 1.3.2.1.

See #6.

38. Does the organization have a Continuous Monitoring program currently in place?

See #21.

39. Has the organization used any automated tools to support the security program in the past such as FISMA Trusted Agent, XaCta, or PureFISMA?

Yes, the current Paying Agent, State Street provides a propriety software application to the

PBGC.

40. How many systems and type make up the current environment? How many major applications, minor applications, and general support systems and where are they located?

See #3.

41. Is there an existing framework for a tool repository? What are the requirements and preferences for the tool type, OS, and whether it should be client server or web based?

See #29. The PBGC has no further requirements and preferences for the tool, beyond what is stated in the SOO.

42. Do you expect the contractor to build the ISMS using an existing environment and platform?

See #29.

43. Do you expect the vendor to come in with a fully licensed tool and the price for the cost of the tool to be included in the quote for this RFP?

File details come from the government source that posted it. Updated .