UPDATED_Attachment_B_FISMA_Services_Task_Order_PWS_11.27.17.pdf
PDF 99 KB Posted
- Attached to
- Risk Management Services- IDIQ Federal contract opportunity
- Solicitation number
- R17PS00246
About this file
UPDATED Attachment B FISMA Services Task Order PWS 11.27.17
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| UPDATED_Attachment_G1_Past_Performance_11.27.17.docx | DOCX document | |
| R17PS00246_Questions_and_Answers.pdf | ||
| UPDATED_Attachment_I_Small_Business_Subcontracting_Plan_11.27.17.docx.doc | DOC document | |
| Amendment_2.pdf | ||
| UPDATED_Attachment_E_ISSO_Services_Pricing_11.27.17.xlsx | XLSX spreadsheet | |
| UPDATED_Attachment_H_Subcontracting_Percentage_Worksheet_for_Small_Business_Commercial_Items_11.27.17.docx | DOCX document | |
| UPDATED_Attachment_G_Past_performance_Questionaire_Cover_Letter_11.27.17.pdf | ||
| UPDATED_Attachment_F_IDIQ_Pricing_11.27.17.xlsx | XLSX spreadsheet | |
| UPDATED_Attachment_C_ISSO_Services_Task_Order_PWS_11.27.17.pdf | ||
| UPDATED_Attachment_D_FISMA_Services_Pricing_11.27.17.xlsx | XLSX spreadsheet | |
| UPDATED_Attachment_A_Performance_Work_Statement_11.27.17.pdf | ||
| UPDATED_R17PS00246_sf_1449_Terms_and_Conditions_11.27.17.pdf | ||
| Amendment_1.pdf | ||
| Pre-_Soliciation_SYNOPSIS__.pdf |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
IT Risk Management Services IDIQ R17PS00246 Page 1 of 9
Attachment B Federal Information Security Management Act Services Task Order PWS
06/15/2017
1. SCOPE
OBJECTIVE - The objective of this contract is to acquire contractor services to assist the United States Bureau of Reclamation (USBR) implement and maintain compliance with Federal Information Security Management Act (FISMA) requirements.
2. BACKGROUND
The USBR Risk Management Services Group (RMSG) is responsible for implementing and maintaining compliance with Federal cybersecurity and related privacy requirements. The RMSG leads the USBR FISMA Compliance Program which manages all activities associated with the National Institutes of Science and Technology (NIST) Risk Management Framework (RMF). USBR requires contractor services to support FISMA compliance activities to include monitoring and tracking compliance status, developing and improving processes, procedures, standards, guidance and templates, providing guidance on security control implementation guidance and process improvement and maturity initiatives. The bureau has approximately thirty authorized information systems, including one cloud system, and most have low or moderate security categorizations. All systems currently follow NIST SP 800-53 rev. 4 requirements and the NIST Risk Management Framework, and most have static point-in-time authorizations while implementing continuous monitoring activities, working toward obtaining ongoing authorizations. Information System documentation, including approximately two-hundred fifty Plans of Actions and Milestones (POA&Ms) is maintained in Cyber Security Assessment Management (CSAM) system. The location for place of performance will be the Denver Federal Center in Colorado, and the ability to obtain a secret clearance will be required.
3. REFERENCES - The following list of documents are required in the performance of this contract:
● NIST SP 800- 18, Guide for Developing Security Plans for Federal Information
Systems http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf
● NIST SP 800-30, Guide for Conducting Risk Assessments http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
● NIST SP 800-34, Contingency Planning Guide for Federal Information Systems http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf
● NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal
Information Systems: A Security Life Cycle Approach http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf
● NIST SP 800-39,Managing Information Security Risk: Organization, Mission, and Information System View http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf
● NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf
● NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
● NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1- Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf
● NIST FIPS 199, Standards for Security Categorization of Federal Information and Information Systems http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf
● FedRAMP Security Assessment Framework, Security Controls and Agency Guide for FedRAMP Authorizations https://www.fedramp.gov/resources/documents/
4. TASKS -The project will be evaluated for completeness of tasks and objectives weekly. The Contractor will receive direct or indirect guidance for work and projects from the COR
4.1. Perform ongoing monitoring of compliance with FISMA documentation requirements to provide timely detection, identification and alerting of non-compliance issues.
4.2. Provide expertise, guidance and recommendations on developing and improving FISMA-related documents and templates to include the following System Security Plan (SSP) elements:
4.2.1. Configuration Management Plan
4.2.2. Contingency Plan
4.2.3. Contingency Plan tests
4.2.4. Continuous Monitoring Plan
4.2.5. Incident Response Plans
4.2.6. Incident Response Plan tests
4.2.7. Federal Information Processing Standard (FIPS) Information Types
4.2.8. Interconnection Security Agreements
4.2.9. Plan of Action & Milestones (POA&M)
4.2.10. Privacy Impact Assessments (PIA)
4.2.11. Risk Assessments
4.2.12. Security control baselines
4.2.13. Security control inheritance
4.2.14. Security Impact Analyses
4.2.15. Business Impact Assessments
4.2.16. SSP implementation statements
4.2.17. Technical Description narratives
4.2.18. System Description narratives
4.2.19. Hardware/Software Inventories
4.3. Provide expertise, guidance and recommendations on IT security training materials.
4.4. Provide expertise, guidance and recommendations on Assessment & Authorization strategies.
4.5. Provide expertise, guidance and recommendations on requirements for cloud-based systems.
http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf https://www.fedramp.gov/resources/documents/ https://www.fedramp.gov/resources/documents/
4.6. Monitor, track and report on the training completion status of personnel required to complete annual IT security training (approximately 5200 individuals); DOI Learn is the main tool used for tracking such training.
4.7. Monitor, track and report on the status of information requests related to IT audit engagements, to include annual FISMA, Financial, OIG and other independent audits.
4.8. Monitor, track and report on the status of annual internal control review activities.
4.9. Prepare FISMA-relevant briefing materials and presentations approximately once per month for a variety of audiences consisting of Individual and Regional Information System Security Officers, Chief Information System Security Manager and Authorizing Official.
4.10. Support FISMA compliance process improvement initiatives to include task automation.
4.11. Provide expertise, guidance and recommendations on FISMA-relevant processes, procedures, guidance, standards and instructional materials.
4.12. Provide technical writing expertise to revise and develop FISMA-relevant processes, procedures, guidance, standards and instructional materials.
4.13. Provide periodic assistance with FISMA-related data calls, analyses or other requests for information.
4.14. Provide expertise, guidance and training on FISMA-compliance related tasks to include developing an SSP, interpreting security control requirements, implementing security controls and conducting self-assessments.
4.15. Support Assessment & Authorization activities.
5. PERFORMANCE REQUIREMENTS SUMMARY
Task No.
Task Description
Performance
Indicator
Performance Standard
Minimum Acceptable Quality Level
4.1 Perform ongoing monitoring of
compliance with FISMA documentation
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Minimum acceptable quality level = 90%.
Failure to perform within the minimum level could result in contract price reduction or other action.
4.2 Provide expertise, guidance and
recommendations on developing and improving FISMA-related documents
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.3 Provide expertise, guidance and 100% on time Product delivery Services may be delivered recommendations on IT security training materials.
delivery of high-quality products compliant with agreed upon delivery schedules and product requirements.
late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.4 Provide expertise, guidance and
recommendations on Assessment & Authorization strategies.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.5 Provide expertise, guidance and
recommendations on requirements for cloud-based systems.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.6 Monitor, track and report on the
training completion status of personnel required to complete annual IT security training.
high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.7 Monitor, track and report on the
status of information requests related to IT audit engagements.
high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.8 Monitor, track and report on the
status of annual internal control review activities.
high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.9 Prepare FISMA-relevant
briefing materials and presentations.
high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other
4.10 Support FISMA compliance
process improvement initiatives.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.11 Provide expertise, guidance and
recommendations on FISMA-relevant processes, procedures, guidance, standards and instructional materials.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.12 Provide technical writing
expertise to revise and develop FISMA-relevant processes, procedures, guidance, standards and instructional materials.
high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.13 Provide periodic assistance with
FISMA-related data calls, analyses or other requests for information.
high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.14 Provide expertise, guidance and
training on FISMA-compliance related tasks to include developing an SSP, interpreting security control requirements, implementing security controls and conducting self-assessments.
100% on time delivery of high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.
4.15 Support Assessment &
Authorization activities.
high-quality products
Product delivery compliant with agreed upon delivery schedules and product requirements.
Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other
6.0 DATA AND REPORTS - The contractor shall provide the following data and reports as follows:
Item No.
(associated with Task)
Description Content Format Medium Delivery
All The COR will define the requirements for assigned products upon task assignment
Content requirements will be directed by the COR upon task assignment
Format to be agreed upon by COR and Project Manager upon task assignment
Electronic format
Deliver to
COR
All Weekly status reports Content requirements will be agreed upon by Contractor, COR and
Contractor’s choice
Electronic format for all reports and any presentation materials – MS Word document for reports, Presentation material format can be determined by Contractor
Deliver to
COR
7. PERSONNEL QUALIFICATIONS
Resumes of all individuals referenced on the contract must be submitted and all individuals will be required to obtain a secret clearance.
7.1. At least five years’ experience with FISMA-related activities to include system security plans, contingency plans, incident response plans, configuration management plans, security control requirements and assessments, Plan of Action and Milestones (POA&M), and training requirements.
7.2. At least five years’ experience in applying NIST SP 800-37 Risk Management principles, interpreting requirements, and developing implementation guidance.
7.3. At least five years’ experience implementing requirements and guidance as indicated in the documents identified in Section 3.0 References.
7.4. At least five years’ experience writing policies, procedures, guidance, standards and instructional materials.
7.5. At least five years’ experience working with interagency teams to design, develop and implement FISMA compliant solutions that meet current and future business requirements and enhance and optimize the existing security architecture.
7.6. Knowledge of and experience with Federal Privacy requirements to include Privacy Impact Assessments PIA and personally identifiable information (PII).
8. DELIVERABLES - The contractor shall submit the following reports in accordance with paragraph
6.0, “DATA AND REPORTS”:
8.1. Electronic copies of document deliverables shall be delivered to the Contracting Officer
Representative (COR) using Microsoft Office (e.g., Microsoft (MS) Word, MS Excel, MS PowerPoint, MS Project, or MS Visio), or pdf for graphics unless otherwise specified at the task level by the COR. A shared environment or SharePoint site will be used to store documentation per the government instructions. Electronic submissions shall be made via email, unless otherwise agreed by the COR. Reclamation shall have ten (10) business days to review each document and provide feedback and comments if necessary. The Contractor shall have five (5) business days to incorporate any comments. A final review shall be conducted with the COR.
The COR's concurrence and approval of the draft and final documents shall constitute acceptance by Reclamation.
8.2. Contractor shall furnish electronic weekly status reports to the COR that includes the results and/or progress of tasks for government review and performance metric review.
8.3. Knowledge Transfer
● Contractor shall provide a strategy to the government on method to ensure that contract staff has sufficient knowledge to perform all development and operation and maintenance activities identified by the Government in a backup role or become the primary leader in the event of staff transitioning out of company.
● A quarterly updated report shall be provided to the government containing at a minimum the following information:
o Task or Application o From Name / Contractor o To Name / Contractor o Date o Percent transition progress
8.4. Staff Replacement Plan
● Contractor staff replacement must meet the experience level of individuals selected for the initial award of this task order.
9. Government Furnished Equipment.
9.1 The government will furnish on site staff with a computer, monitor, mouse, and keyboard.
Instructions, Conditions and Notices to Offerors
1. Government anticipates making one (1) firm-fixed price award with a period of performance of One year.
2. Format:
a. Submit all copies IAW Section III under General Proposal Instructions.
b. Submit in Arial, Calibri, or Times New Roman font, 11 point or larger with 1” margins.
c. All vendors are required to submit all documents associated with Attachment B in Section III to include Technical Approach, Key Personnel and, Past Performance.
d. All vendors are required to submit Volume V Attachment D: Pricing.
3. Content:
a. Technical Approach (25 page limit)
i. Technical approach
ii. Knowledge transfer plan
b. Key Personnel Experience. Include the following information:
i. The names of specific key personnel to be assigned to perform the work IAW the Performance Work Statement including education, background and experience, accomplishments, and other pertinent information;
ii. A list of alternate personnel sources to be utilized in the event proposed personnel are not available as planned (Include full resume by name of all additional personnel listed.)
iii. Limit Key Personnel(alternate and non-alternate)/Experience to five (5) 8-1/2 inch by 11 inch pages each. (Not included in 25 page count for technical approach).
c. The Past Performance shall include a list of three (3) references of projects similar to this requirement under this solicitation which the offeror has completed during the last (3) years.
For each project, include: (no page limit)
(i) Name of the project;
(ii) Description of the work;
(iii) Contract number, date and type;
(iv) Name and address of the acquiring Government agency or commercial customer;
(v) Initial contract amount and final contract amount;
(vi) Name(s) and telephone number(s) of references from the acquiring agency or customer who may be contacted for further information.
d. All pricing information shall be included on Attachment D.
The Government will award a contract resulting from this solicitation to the responsible offeror whose offer conforming to the solicitation will be most advantageous to the Government, price and other factors considered. The following factors shall be used to evaluate offers:
(a) Award will be based on the best value to the government, price and other factors considered.
1. Technical Approach: Basis of Evaluation: Offers will be evaluated to determine the soundness of the technical approach and methodology most suitable to this effort and the knowledge transfer plan.
2. Key Personnel and Experience: Basis of Evaluation: The resumes submitted by the Offeror will be evaluated to assess the availability and qualifications of the proposed staff, their experience in similar projects, and their capability to fully and professionally accomplish the objectives stated herein. The successful contractor shall maintain the level of expertise covered by the professional staff proposed with the offer for the duration of the contract. If a staff member leaves the project, his/her replacement must have at a minimum the same level of experience, education, etc. Any replacement staff is subject to the review and acceptance of the COTR. Alternate personnel resumes are required.
3. Past performance: Basis of Evaluation: The quote will be evaluated to assess the corporate experience of the Offeror with respect to projects similar in scope and size to the work described herein within the last (3) years.
4. Price: Basis of Evaluation: Offerors aggregate price for Task Order will be evaluated.
The government will perform an evaluation where key personnel and technical approach is more important than price and past performance and select the offer that provides the best value.
| 1. SCOPE |
| 2. BACKGROUND |
| 3. REFERENCES - The following list of documents are required in the performance of this contract: |
| 4. TASKS -The project will be evaluated for completeness of tasks and objectives weekly. The Contractor will receive direct or indirect guidance for work and projects from the COR |
| 5. PERFORMANCE REQUIREMENTS SUMMARY |
| 7. PERSONNEL QUALIFICATIONS |
| 8. DELIVERABLES - The contractor shall submit the following reports in accordance with paragraph 6.0, “DATA AND REPORTS”: |
File details come from the government source that posted it.