UPDATED_Attachment_C_ISSO_Services_Task_Order_PWS_11.27.17.pdf

PDF 98 KB Posted

Attached to
Risk Management Services- IDIQ Federal contract opportunity
Solicitation number
R17PS00246
Issued by
Department of the Interior Bureau of Reclamation

About this file

UPDATED Attachment C ISSO Services Task Order PWS 11.27.17

View the file

Other files for this federal contract opportunity

Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

IT Risk Management Services IDIQ R17PS00246 Page 1 of 9

Attachment C Information System Security Officer Services Task Order PWS

06/15/2017

1. SCOPE

OBJECTIVE - The objective of this contract is to acquire contractor services to assist the United States Bureau of Reclamation (USBR) in fulfilling Information System Security Officer (ISSO) responsibilities.

2. BACKGROUND

The USBR Risk Management Services Group (RMSG) is responsible for implementing and maintaining compliance with Federal cybersecurity, and related privacy, requirements. The RMSG leads the USBR FISMA Compliance Program which manages all activities associated with the National Institutes of Science and Technology (NIST) Risk Management Framework (RMF). The RMSG also provides security-as-a-service support to system owners by providing resources to fulfill ISSO responsibilities.

USBR requires contractor services to support federal staff in fulfilling ISSO responsibilities in accordance with NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach for systems to include the following:

System FIPS 199

Categorization Description

Electronic Service Agreement Module (ESAM)

Low Web-based application on shared infrastructure included in BOR GSS.

Electronic Time and Attendance System (ETAS)

Moderate Web-based application on shared infrastructure included in BOR GSS.

Budget and Reporting System

(BARS)

Low Application-as-a-Service cloud application that inherits the majority of controls from approved Cloud Service Providers.

BOR General Support Systems

(GSS)

Moderate Large, distributed and decentralized GSS;

primarily infrastructure components.

Reclamation Water Information System (RWIS)

Low Public facing web site to allow stakeholders to review water related data in a manner that is readable format.

Reclamation Services and Applications for Mission Support (RSAMS)

Moderate Several small-scale, minor applications on shared infrastructure included in BOR GSS.

Research and Development Applications (RWIS, RADIMS, RISE etc.)

Moderate Several small-scale minor applications on shared infrastructure.

3. REFERENCES - The following list of documents are required in the performance of this contract:

● NIST SP 800- 18, Guide for Developing Security Plans for Federal Information Systems http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf

● NIST SP 800-30, Guide for Conducting Risk Assessments http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf

IT Risk Management Services IDIQ R17PS00246 Page 2 of 9 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

● NIST SP 800-34, Contingency Planning Guide for Federal Information Systems http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf

● NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal

Information Systems: A Security Life Cycle Approach http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf

● NIST SP 800-39,Managing Information Security Risk: Organization, Mission, and Information System View http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf

● NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf

● NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf

● NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1- Rev1.pdf

● NIST FIPS 199, Standards for Security Categorization of Federal Information and Information Systems http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf

● FedRAMP Security Assessment Framework, Security Controls and Agency Guide for FedRAMP Authorizations https://www.fedramp.gov/resources/documents/

4. TASKS - The contractor shall perform ISSO tasks in accordance with NIST SP 800-37 and task order requirements. The work shall be completed during the period of performance. The project will be evaluated for completeness of tasks and objectives weekly. The Contractor will receive direct or indirect guidance for work and projects from the COR. All work will be performed in the Denver office.

4.1. Ensure that the appropriate operational cybersecurity posture is maintained for assigned IT systems.

4.2. Develop, update and maintain the System Security Plan (SSP) for assigned systems to include:

4.2.1. Configuration Management Plan

4.2.2. Contingency Plan

4.2.3. Contingency Plan tests

4.2.4. Continuous Monitoring Plan

4.2.5. Incident Response Plans

4.2.6. Incident Response Plan tests

4.2.7. Federal Information Processing Standard (FIPS) Information Types

4.2.8. Interconnection Security Agreements

4.2.9. Plan of Action & Milestones (POA&M)

http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf https://www.fedramp.gov/resources/documents/ https://www.fedramp.gov/resources/documents/

IT Risk Management Services IDIQ R17PS00246 Page 3 of 9

4.2.10. Privacy Impact Assessments (PIA)

4.2.11. Risk Assessments

4.2.12. Security control baselines

4.2.13. Security control inheritance

4.2.14. Security Impact Analyses

4.2.15. Business Impact Analyses

4.2.16. SSP implementation statements

4.2.17. Technical Description narratives

4.2.18. System Description narratives

4.2.19. Hardware/Software Inventory

4.3. Conduct Contingency Plan, Recovery Plan and Incident Response tests for assigned IT systems.

4.4. Participate in Incident Response activities for assigned IT systems.

4.5. Advise system owners on all matters, technical and otherwise, involving the security of assigned IT systems.

4.6. Develop standard operating procedures in accordance with security control requirements.

4.7. Perform continuous monitoring of security controls to ensure that they continue to be implemented correctly, operating as intended and producing the desired outcome with respect for meeting the cybersecurity requirements for assigned IT systems.

4.8. Work with technical teams to mitigate security control deficiencies for assigned IT systems.

4.9. Assess the cybersecurity impact of changes to assigned IT systems.

4.10. Conduct self-assessments of security controls, identify weaknesses and track remediation activities in Plan of Action and Milestones (POA&M).

4.11. Conduct technical vulnerability assessments and prioritize and track remediation efforts.

4.12. Manage the POA&M process for designated IT systems.

4.13. Provide the required system access, information, and documentation to security assessment and audit teams.

4.14. Participate in security assessments and audits for assigned systems and facilitate obtaining evidence for data requests.

4.15. Complete required A&A activities on assigned IT systems.

4.16. Assist federal staff in providing expertise and training to Reclamation ISSOs.

4.17. Assist federal staff in assessing new applications, identifying applicable NIST SP 800-37 RMF requirements and advising system owners of the process.

5. PERFORMANCE REQUIREMENTS SUMMARY

IT Risk Management Services IDIQ R17PS00246 Page 4 of 9

Task No.

Deliverable

Performance

Standard

Draft Review

Completion Date

4.2 Develop, update and maintain

the System Security Plan (SSP) for assigned systems

100% on time delivery of high-quality products

Product delivery compliant with agreed upon delivery schedules and product requirements.

Once assessment begins on any given system must meet required deadlines established by the FISMA team.

4.3 Conduct Contingency Plan, Recovery Plan and Incident Response tests for assigned IT systems.

100% on time delivery of high-quality products

Product delivery compliant with agreed upon delivery schedules and product requirements.

Product delivery must occur within 30 days of start of testing.

4.4 Participate in Incident Response

activities for assigned IT systems.

100% on time delivery of high-quality products

Product delivery compliant with agreed upon delivery schedules and product requirements.

Product delivery must occur within 30 days of start of testing.

4.6 Develop standard operating

procedures in accordance with security control requirements.

100% on time delivery of high-quality products

Product delivery compliant with agreed upon delivery schedules and product requirements.

Must submit draft documents 30 days after beginning work on assigned SOP’s, BOR Staff will have 7 Business days to provide feedback.

Completion of documents from review is required within 15 business days or may result in contract price reduction or other action.

4.12 Manage the POA&M process

for designated IT systems.

100% on time delivery of high-quality products

Product delivery compliant with agreed upon delivery schedules and product requirements.

Management of outstanding POA&Ms will occur at the beginning of every month and evidence is reviewed as received. Status update should occur by the 15th of the month for every POA&M. Completion of WCVF must be completed as they occur.

Review of WCVF will be set at 10 days and final documentation will be needed from contractor within 10 days of the

IT Risk Management Services IDIQ R17PS00246 Page 5 of 9 review. Failure to perform could result in contract price reduction or other action.

4.15 Complete required A&A

activities on assigned IT systems.

100% on time delivery of high-quality products

Product delivery compliant with agreed upon delivery schedules and product requirements.

Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.

4.16 Assist federal staff in providing

expertise and training to Reclamation ISSOs.

100% on time delivery of high-quality products

Product delivery compliant with agreed upon delivery schedules and product requirements.

Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.

4.17 Assist federal staff in assessing

new applications, identifying applicable NIST SP 800-37 RMF requirements and advising system owners of the process.

100% on time delivery of high-quality products

Product delivery compliant with agreed upon delivery schedules and product requirements.

Services may be delivered late no more than 10% of the time. Failure to perform within the 10% could result in contract price reduction or other action.

6.0 DATA AND REPORTS - The contractor shall provide the following data and reports as follows:

Item No.

(associated with Task)

Description Content Format Medium Delivery

All The COR will define the requirements for assigned products upon task assignment

Content requirements will be directed by the COR upon task assignment

Format to be agreed upon by COR and contractor project manager upon task assignment

Electronic format

Deliver to

COR

All Weekly status reports Content requirements will be agreed upon by Contractor and COR

Contractor’s choice

Electronic format for all reports and any presentation materials – MS Word document for reports, Presentation material format can

Deliver to COR on a weekly basis

IT Risk Management Services IDIQ R17PS00246 Page 6 of 9 be determined by Contractor

7. PERSONNEL QUALIFICATIONS

7.1. Each contract employee must possess at a minimum 8 years of experience with 5 years specialized experience and IT Certification or 6 years specialized experience in defining computer security requirements. Must be able to evaluate approved security product capabilities and develop solutions

7.2. Knowledge of and experience with FISMA-related activities to include system security plans, contingency plans, incident response plans, configuration management plans, security control requirements and assessments, Plan of Action and Milestones (POA&M), and training requirements.

7.3. Knowledge of and experience in applying NIST SP 800-37 Risk Management principles, interpreting requirements and developing implementation guidance.

7.4. Knowledge of and experience implementing requirements and guidance as indicated in the documents identified in Section 3.0 References.

7.5. Knowledge and experience with performing information system continuous monitoring of security controls to ensure that they continue to be implemented correctly, operating as intended and producing the desired outcome with respect for meeting the security requirements.

7.6. Knowledge and experience in writing policies, procedures, guidance, standards and instructional materials.

7.7. Team to design, develop and implement FISMA compliant solutions that meet current and future business requirements and enhance and optimize the existing security architecture.

7.8. Knowledge of and experience with Federal Privacy requirements to include Privacy Impact Assessments PIA and personally identifiable information (PII).

7.9. Recommended IT certifications include CISSP, CISA, CISM and GIAC?

7.10. Experience working as an ISSO in an environment with multiple levels of systems.

8. DELIVERABLES - The contractor shall submit the following reports in accordance with paragraph

6.0, “DATA AND REPORTS”:

8.1. Electronic copies of document deliverables shall be delivered to the Contracting Officer

Representative (COR) using Microsoft Office (e.g., Microsoft (MS) Word, MS Excel, MS PowerPoint, MS Project, or MS Visio), or pdf for graphics unless otherwise specified at the task level by the COR. A shared environment or SharePoint site will be used to store documentation per the government instructions. Electronic submissions shall be made via email, unless otherwise agreed by the COR. Reclamation shall have fifteen (15) business days to review each document and provide feedback and comments if necessary. The Contractor shall have five (5) business days to incorporate any comments. A final review shall be conducted with the COR.

The COR's concurrence and approval of the draft and final documents shall constitute acceptance by Reclamation.

IT Risk Management Services IDIQ R17PS00246 Page 7 of 9

8.2. Contractor shall furnish electronic weekly status reports to the COR that includes the results and/or progress of tasks for government review and performance metric review.

8.3. Knowledge Transfer

● Contractor shall provide a strategy to the government on method to ensure that contract staff has sufficient knowledge to perform all development and operation and maintenance activities identified by the Government in a backup role or become the primary leader in the event of staff transitioning out of company.

● A quarterly updated report shall be provided to the government containing at a minimum the following information:

o Task or Application o From Name / Contractor o To Name / Contractor o Date o Percent transition progress

8.4. Staff Replacement Plan

● Contractor staff replacement must meet the experience level of individuals originally selected for the original IDIQ.

9. Government Furnished Equipment.

9.1 The government will furnish on site staff with a computer, monitor, mouse, and keyboard.

IT Risk Management Services IDIQ R17PS00246 Page 8 of 9

Instructions, Conditions and Notices to Offerors

1. Government anticipates making one (1) firm-fixed price award with a period of performance of one year.

2. Format:

a. Submit all copies IAW Vol IV under General Proposal Instructions.

b. Submit in Arial, Calibri, or Times New Roman font, 11 point or larger.

c. All vendors are required to submit all documents associated with Attachment C in Section IV to include Technical Approach, Key Personnel and, Past Performance.

d. All vendors are required to submit Volume VI Attachment E: Pricing.

3. Content:

a. Technical Approach. (25 page limit for a.)

i. Technical Approach

ii. Knowledge transfer plan.

b. Key Personnel Experience. Include the following information:

i. The names of specific key personnel to be assigned to perform the work IAW the Performance Work Statement to include education, background and experience, accomplishments, and other pertinent information;

ii. A list of alternate personnel sources to be utilized in the event proposed personnel are not available as planned (Include full resume by name of all additional personnel listed.)

iii. Limit Key Personnel(alternate and non-alternate)/Experience to five (5) 8-1/2 inch by 11 inch pages each. (Not included in 25 page count for technical approach).

c. The Past Performance shall include a list of three (3) references of projects similar to this requirement under this solicitation which the offeror has completed during the last (3) years.

For each project, include: (No page limit)

(i) Name of the project;

(ii) Description of the work;

(iii) Contract number, date and type;

(iv) Name and address of the acquiring Government agency or commercial customer;

(v) Initial contract amount and final contract amount;

(vi) Name(s) and telephone number(s) of references from the acquiring agency or customer who may be contacted for further information.

d. All pricing information shall be included on attachment E.

The Government will award a contract resulting from this solicitation to the responsible offeror whose offer conforming to the solicitation will be most advantageous to the Government, price and other factors considered. The following factors shall be used to evaluate offers:

Award will be based on the best value to the government, price and other factors considered.

IT Risk Management Services IDIQ R17PS00246 Page 9 of 9

1. Technical Approach: Basis of Evaluation: Offers will be evaluated to determine the soundness of the technical approach and methodology most suitable to this effort and the knowledge transfer plan.

2. Key Personnel and Experience: Basis of Evaluation: The resumes submitted by the Offeror will be evaluated to assess the availability and qualifications of the proposed staff, their experience in similar projects, and their capability to fully and professionally accomplish the objectives stated herein. The successful contractor shall maintain the level of expertise covered by the professional staff proposed with the offer for the duration of the contract. If a staff member leaves the project, his/her replacement must have at a minimum the same level of experience, education, etc. Any replacement staff is subject to the review and acceptance of the COTR. Alternate personnel resumes are required.

3. Past performance: Basis of Evaluation: The quote will be evaluated to assess the corporate experience of the Offeror with respect to projects similar in scope and size to the work described herein within the last (3) years.

4. Price: Basis of Evaluation: Offerors aggregate price for Task Order will be evaluated.

The government will perform an evaluation where key personnel and technical approach is more important than price and past performance and select the offer that provides the best value.

1. SCOPE
2. BACKGROUND
3. REFERENCES - The following list of documents are required in the performance of this contract:
4. TASKS - The contractor shall perform ISSO tasks in accordance with NIST SP 800-37 and task order requirements. The work shall be completed during the period of performance. The project will be evaluated for completeness of tasks and objectives we...
5. PERFORMANCE REQUIREMENTS SUMMARY
7. PERSONNEL QUALIFICATIONS
8. DELIVERABLES - The contractor shall submit the following reports in accordance with paragraph 6.0, “DATA AND REPORTS”:

File details come from the government source that posted it.