R16PS01467_Attachment_A_Performance_Work_Statement_.pdf
PDF 126 KB Posted
- Attached to
- ICS Support Federal contract opportunity
- Solicitation number
- R16PS01467
About this file
Attachment A Performance Work Statement
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions_and_Answers.pdf | ||
| R16PS01467_Amendment_One.pdf | ||
| R16PS01467_Terms_Conditions_and_Evaluation_Factors.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment A: Performance Work Statement 8/15/2016 ICS Support R16PS01467
1. SCOPE
OBJECTIVE - The objective of this contract is to acquire contractor services to assist the United States Bureau of Reclamation (USBR) with Industrial Control System (ICS) cybersecurity activities.
2. BACKGROUND
The USBR Risk Management Services Group (RMSG) is responsible for implementing and maintaining compliance with Federal cybersecurity requirements. The RMSG leads the ICS Cybersecurity Program, which is responsible for establishing risk-based, consistent and repeatable processes for securing ICS based on system function and the risk the system poses to human life, property, the environment.
These processes will consider ICS currently in operation and subject to improvement and modification, ICS currently in development or under construction, and new ICS deployments being considered or within the planning stage.
3. REFERENCES - The following list of documents are required in the performance of this contract:
• NIST SP 800- 18, Guide for Developing Security Plans for Federal Information Systems http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf
• NIST SP 800-30, Guide for Conducting Risk Assessments http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
• NIST SP 800-34, Contingency Planning Guide for Federal Information Systems http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf
• NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information
Systems: A Security Life Cycle Approach http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf
• NIST SP 800-39,Managing Information Security Risk: Organization, Mission, and Information System View http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf
• NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf
• NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
• NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1- Rev1.pdf
• NIST SP 800-82, Guide to Industrial Control System Security http://csrc.nist.gov/publications/nistpubs/800-82/SP800-82-final.pdf
• NIST FIPS 199, Standards for Security Categorization of Federal Information and Information Systems http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-82/SP800-82-final.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf
4. TASKS - The contractor shall perform tasks in accordance with requirements. The work shall be completed during the period of performance. The project will be evaluated for completeness of tasks and objectives weekly. To be performed at the Denver Federal Center.
4.1. Perform ICS security assessments in support of Security Assessments and Authorizations (A&A).
4.2. Conduct technical evaluations of ICS to identify weaknesses and recommend appropriate countermeasures.
4.3. Conduct ICS vulnerability, risk, and threat assessments and recommend risk reduction measures.
4.4. Identify ICS capabilities, dependencies, and component level vulnerabilities.
4.5. Conduct security impact analyses of changes to ICS.
4.6. Evaluate effectiveness of ICS contingency and recovery plans, exercises and training and recommend improvements to improve system resilience.
4.7. Develop and document minimum ICS cybersecurity requirements and best practices.
4.8. Develop continuous monitoring plans, metrics for ICS.
4.9. Develop options and recommendations for performing centralized continuous monitoring activities on ICS that reside on isolated networks.
4.10. Support cybersecurity process improvement initiatives to include task automation.
4.11. Support efforts to develop ICS cybersecurity dashboards.
4.12. Support efforts to identify, document and categorize ICS asset inventories.
4.13. Support the development and implementation of an ICS cybersecurity strategy and implementation plan.
4.14. Support the development of a cybersecurity framework for implementation across ICS deployments, leveraging existing cybersecurity guidance.
4.15. Support ICS training initiatives.
4.16. Prepare ICS-relevant briefing materials and presentations.
4.17. Provide expertise, guidance and recommendations on ICS-relevant processes, procedures, guidance, standards and instructional materials.
4.18. Provide periodic assistance with ICS-related data calls, analyses or other requests for information.
5. PERFORMANCE REQUIREMENTS SUMMARY
Task No.
Task Description
Performance
Indicator
Performance Standard
Minimum Acceptable Quality Level
4.1 Perform ICS security
assessments in support of Security Assessments and Authorizations (A&A).
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.2 Conduct technical evaluations of
ICS to identify weaknesses and recommend appropriate countermeasures.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.3 Conduct ICS vulnerability, risk, and threat assessments and recommend risk reduction measures.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.4 Identify ICS capabilities, dependencies, and component level vulnerabilities.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.5 Conduct security impact
analyses of changes to ICS.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
Acceptable Quality Level
4.6 Evaluate effectiveness of ICS
contingency and recovery plans, exercises and training and recommend improvements to improve system resilience.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.7 Develop and document
minimum ICS cybersecurity requirements and best practices.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.8 Develop continuous monitoring
plans, metrics for ICS.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.9 Develop options and
recommendations for performing centralized continuous monitoring activities on ICS that reside on isolated networks.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.10 Support cybersecurity process
improvement initiatives to include task automation.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract
Acceptable Quality Level
4.11 Support efforts to develop ICS
cybersecurity dashboards.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.12 Support efforts to identify, document and categorize ICS asset inventories.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.13 Support the development and
implementation of an ICS cybersecurity strategy and implementation plan.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.14 Support the development of a
cybersecurity framework for implementation across ICS deployments, leveraging existing cybersecurity guidance.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.15 Support ICS training initiatives. 100% on time
delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract
Acceptable Quality Level
4.16 Prepare ICS-relevant briefing
materials and presentations.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.17 Provide expertise, guidance and
recommendations on ICS-relevant processes, procedures, guidance, standards and instructional materials.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.18 Provide periodic assistance with
ICS-related data calls, analyses or other requests for information.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract
5.0 DATA AND REPORTS - The contractor shall provide the following data and reports as follows:
Item No.
(associated with Task)
Description Content Format Medium Delivery
All Weekly status reports
Content requirements will be agreed upon by Contractor, COR and
TSAL
Contractor’s choice
Electronic format for all reports and any presentation materials – MS Word document for reports, Presentation material format can be determined by Contractor
Deliver to COR and
TSAL
6. PERSONNEL QUALIFICATIONS
6.1. Expert level knowledge of and experience with FISMA-related activities to include system security plans, contingency plans, incident response plans, configuration management plans, security control requirements and assessments, Plan of Action and Milestones (POA&M), and training requirements.
6.2. Expert level knowledge and experience in applying NIST SP 800-37 Risk Management principles, interpreting requirements, and developing implementation guidance.
6.3. Experience conducting security assessments at civilian government agencies including creating SAPs, SARs and all the relevant components of each.
6.4. Experience conducting security assessments in accordance with NIST SP 800-53A guidance
6.5. Experience using the NIST SP 800-37 Risk Management Framework.
6.6. Experience conducting Technical Vulnerability Assessments, using vulnerability scanning tools and analyzing results.
6.7. Expert level knowledge of and experience implementing requirements and guidance as indicated in the documents identified in Section 3.0 References.
6.8. Expert level knowledge and experience writing policies, procedures, guidance, standards and instructional materials.
6.9. Ability to work with Reclamation and interagency teams to design, develop and implement
FISMA compliant solutions that meet current and future business requirements and enhance and optimize the existing security architecture.
6.10. Knowledge and experience with Federal Privacy requirements to include Privacy Impact Assessments PIA and personally identifiable information (PII).
6.11. Extensive knowledge of cyber security threats and vulnerabilities for Industrial Control Systems, and mitigation techniques.
6.12. Extensive knowledge of information security techniques and practices such as risk and threat analysis, vulnerability management, incident detection and response, continuous monitoring, and vulnerability assessments.
Expert = Bachelor’s Degree in Computer Science, Information Resource Management, Information Systems, or equivalent. Certified Information Systems Security Professional (CISSP) or equivalent certification.
At least 10 years’ experience in IT systems security with a minimum 5 years of combined experience in the data security aspects of IT and/or the documented ability to conduct security audits and certifications in support of federal accreditation decisions utilizing government security programs and standards including Office of Management and Budget Circular A-130 and National Institute of Standards 800 Series special publications and manuals. At least 2 years specialized experience with IT security aspects of Industrial Control Systems.
7. DELIVERABLES - The contractor shall submit the following reports in accordance with paragraph 5.0, “DATA AND REPORTS”:
7.1. Electronic copies of document deliverables shall be delivered to the Contracting Officer
Representative (COR) using Microsoft Office (e.g., Microsoft (MS) Word, MS Excel, MS
PowerPoint, MS Project, or MS Visio), or pdf for graphics. A shared environment or SharePoint site will be used to store documentation per the government instructions. Electronic submissions shall be made via email. Reclamation shall have fifteen (15) business days to review each document and provide feedback and comments if necessary. The Contractor shall have five (5) business days to incorporate any comments. A final review shall be conducted with the COR. The COR's concurrence and approval of the draft and final documents shall constitute acceptance by Reclamation.
7.2. Contractor shall furnish electronic weekly status reports to the COR that includes the results and/or progress of tasks for government review and performance metric review.
7.3. Knowledge Transfer
• Contractor shall provide a strategy to the government on method to ensure that contract staff has sufficient knowledge to perform all development and operation and maintenance activities identified by the Government in a backup role or become the primary leader in the event of staff transitioning out of company.
• A quarterly updated report shall be provided to the government containing at a minimum the following information:
o Task or Application o From Name / Contractor o To Name / Contractor o Date o Percent transition progress
7.4. Staff Replacement Plan
• Contractor shall provide a staff replacement plan SUBSTITUTION OF KEY PERSONNEL AND
OTHER PERSONNEL CONSIDERATIONS.
| 1. SCOPE |
| 2. BACKGROUND |
| 3. REFERENCES - The following list of documents are required in the performance of this contract: |
| 4. TASKS - The contractor shall perform tasks in accordance with requirements. The work shall be completed during the period of performance. The project will be evaluated for completeness of tasks and objectives weekly. To be performed at the Denver... |
| 5. PERFORMANCE REQUIREMENTS SUMMARY |
| 6. PERSONNEL QUALIFICATIONS |
| 7. DELIVERABLES - The contractor shall submit the following reports in accordance with paragraph 5.0, “DATA AND REPORTS”: |
File details come from the government source that posted it. Updated .