RFI Attachment 4-Draft_IA-RMF-IDIQ_Labor Categories_V1_04-17-23.xlsx

XLSX spreadsheet 30 KB Posted

Attached to
USCG Information Assurance (IA) Risk Management Framework (RMF) Services Federal contract opportunity
Solicitation number
70Z04423IESDIAB01
Issued by
Department of Homeland Security US Coast Guard

View the file

Other files for this federal contract opportunity

Other files attached to USCG Information Assurance (IA) Risk Management Framework (RMF) Services, newest first.
File Type Posted
RFI Vendor Question-Comment Summary - IA RMF RFI - v08-10-23.xlsx XLSX spreadsheet
RFI Attachment 6-Question-Comment Form - v1_05-22-23.xls XLS spreadsheet
RFI Attachment 3-Draft_IA-RMF-IDIQ_Scope of Work_20230525_v2.0.4.docx DOCX document
RFI Attachment 1-Questionaire_RFI ESDIAB01_05-25-23.docx DOCX document
RFI Attachment 2 - Draft_IA-RMF-IDIQ_RFP_v4_05-22-23.docx DOCX document
RFI Attachment 5-Draft_IA-RMF_C5ISCTaskOrderPWS_v0.3_05-25-23.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Labor Categories

Labor CategoryLabor Category DescriptionLevelMinimum Years ExperienceMinimum ExperienceMinimum Education/TrainingMinimum CertificationDoD Cyber Workforce FrameworkWork Role ID
Program ManagerServes as the contract manager and administrator over the entire contract effort including IDIQ and task/delivery orders. Acts as the primary interface and point of contact with Government program authorities and representatives on technical and contract administration issues. Manages contract support operations involving personnel at diverse locations. Organizes, directs, and coordinates planning and production of all contract support activities. Must have demonstrated communications skills with all levels of management. Interfaces with Government managers including the Contracting Officers and the Contracting Officer's Representatives (COR). Under stringent timeframes, assembles and recruits personnel necessary to perform assigned tasks. Establishes and alters (as necessary) management structure to effectively direct contract support activities. Assigns, schedules, and reviews work of subordinates. Ensures conformance to contract and task order specifications and contract provisions. Interprets policies, purposes, and goals of the organization for subordinates. Must be capable of negotiating and making binding decisions for the company. Supervises program operations by developing management procedures, planning and directing program execution, monitoring and reporting progress. Manages and controls financial and administrative aspects of the program with respect to contract requirements.IV10Demonstrated capability in managing multitask contracts and/or subcontracts of various types and complexity; expertise in the management and control of funds and resources; demonstrated information technology expertise and communications skills to be able interface with all levels of management.Bachelor's degree in Computer Science, Information Systems, Engineering, Business, or other related disciplinePMP, IAM IIProgram Manager801
III7
II5
I3
Project ManagerServes as the central point of contact for task/delivery orders and interfaces with the Contracting Officers Representatives for tasks. Establishes and enforces procedures to assure that all tasks are performed in accordance with applicable standards and quality requirements. Assigns duties and reviews work of subordinates and subcontractors. Meets and confers with CG management officials regarding status of specific technical activities and progress. Resolves problems, issues or conflicts as required, and ensures that program schedules, performances, and deliverables are met.III7Demonstrated information technology expertise and direct hands-on experience in the areas of Information Assurance, Cybersecurity, and project management; demonstrated communication skills to be able to interface with all levels of management; strong project management skills in addition to interpersonal, writing, and presentation skills; experience supervising and managing projects of at least 15 personnel, subordinate groups, and diverse locations.Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related disciplinePMP, IAM IIIT Project Manager802
II5
I3
Program AnalystPossess demonstrated knowledge and experience applying methodologies and principles to address client needs. Applies analytic techniques in the evaluation of task objectives and contributes to the implementation of strategic direction. Performs analyst functions including data gathering, interviewing, data modeling, testing, and creation of performance measurement to support objectives. Conducts activities in support of project team's objectives. Works closely with other members of the project team.III7Demonstrated experience supporting the implementation of the DIACAP, RMF, DCIS 6/3, NIST, ICD 505, and DODIIS requirements; demonstrated experience in analyzing and preparing program documents and reports; knowledge and capability in developing program requirements, documentation, financial, and/or technical requirements; strong writing and presentation skills; demonstrated communication skills to interface with all levels of management.Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related disciplineIAM IIIT Program Auditor805
II5
I3
Security Control AssessorConducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controlsIII6Demonstrated experience in determining how a security system should work including its resilience an dependability capabilities. Demonstrated experience in discerning the protection needs of information systems, networks, and platform information technology. Demonstrated experience in applying the principles of confidentiality, integrity, and availability.Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related disciplineIAM IISecurity Control Assessor612
II4
I2
Information System Security OfficerAnalyzes and defines security requirements. Performs risk analysis and security contol assessment and audit services, develops analytical reports as required. May be required to perform or assist in one or more of the following areas: Risk and Vulnerability Assessments; Cyber Hunting activities; conducting Penetration Testing and scanning; assessment of system security for compliance of applications; security of computer network hardware; operating system utility/support software; disaster recovery; incident response and digital forensics; application assessment; vulnerability threat management; cloud security; contingency planning; social engineering; and the development of security policies and procedures. Possess and apply expertise on multiple complex work assignments.III6Demonstrated experience in discerning the protection needs of information systems, networks, and platform information technology. Demonstrated experience in applying the principles of confidentiality, integrity, and availability. Demonstrated experience implementing the RMF process especially for system categorization and control selection, implementation, and assessment, as well as continuous monitoring.Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related disciplineIAM IIDependent upon Task Order role requirementsTBD
II4
I2
Information System Security EngineerProvides technical input, recommendations, and assistance with the implementation of both higher and granular-level cyber security approaches, methods and solutions that incorporate and maintain compliance to requirements resulting from laws, regulations, and other pertinent guidance.III7Demonstrated experience in
Information Security (INFOSEC); computer security; cryptography; network security; assessment and authorization; incident response investigations; risk analysis; threat and vulnerability scanning, analysis, and management. Demonstrated experince with system and security engineering principles such as secure architecture, design, and development, and defense in depth. Demonstrated communication skills to interface with all levels of management, as well as appropriate use of style and language for audience.Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related disciplineIAT IIDependent upon Task Order role requirementsTBD
II5
I3
Database SpecialistAdminister databases and/or data management systems that allow for the storage, query, and utilization of dataIII6Demonstrated experience in establishing data security controls, maintaining databases, and optimizing database performance.Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related disciplineIAT I, Computing Environment CertificationDatabase Administrator421
II4
I2
Data AnalystAnalyzes and interprets data from multiple disparate sources and builds visualizations and dashboards to report insights.III6Demonstrated experience in the following areas: conducting queries and developing algorityms to analyze data structures; generating queries and reports; identifying data patterns/relationships; statistics and associated techniques; use of data analysis tools and writing scripts. Demonstrated communications skills to interface with all levels of management. Strong interpersonal skills to include approachability, effective listening, and appropriate use of style and language for the audience.Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related disciplineIAT IIData Analyst422
II4
I2

Core Reqmts for ALL Roles

Core Requirements
Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity.
Knowledge of cybersecurity principles.
Knowledge of cyber threats and vulnerabilities.
Knowledge of computer networking concepts and protocols, and network security methodologies.
Knowledge of specific operational impacts of cybersecurity lapses.
Knowledge of cloud computing service models Software as Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS).
Knowledge of cloud computing deployment models in private, public, and hybrid environments and the difference between on-premises and off-premises environments.

Substitution Tables

Because of the specialized skills required for highly adaptive cybersecurity work, experience is often substituted for degree or degree for experience as shown in the substitution table.Level Comparison
Degree Substitution TableLevel IndicatorAlso Know As
DegreeRelated Work Experience SubstitutionRelated Degree and Experience SubstitutionLevel IVSenior
Associate's2 year’s work experience may be
substituted for an Associate’s Degree2 year’s work experience may be
substituted for an Associate’s DegreeLevel IIISenior or SME
Bachelor's4 year’s work experience may be substituted for a Bachelor’s DegreeAssociate’s Degree plus 2 years work experience may be substituted for a
Bachelor’s DegreeLevel IIJourneyman or Mid
Master's6 year’s work experience may be substituted for a Master’s DegreeBachelor’s Degree plus 2 years work experience may be substituted for a Master’s DegreeLevel IJunior
Doctorate10 year’s work experience may be substituted for a Doctorate DegreeBachelor’s Degree plus 6 years work experience, or a Master’s Degree plus 4 years work experience may be

substituted for a Doctorate

Baseline Certifications Approved Baseline Certifications Reference Site: https://public.cyber.mil/cw/cwmp/dod-approved-8570-baseline-certifications/ Date: November 17, 2022

IAT Level I2 IAT Level II2 IAT Level III This table provides a list of DoD approved IA baseline certifications aligned to each category and level of the IA Workforce. Personnel performing IA functions must obtain one of the certifications required for their position, category/specialty and level to fulfill the IA baseline certification requirement. Most IA levels within a category or specialty have more than one approved certification and a certification may apply to more than one level.

An individual needs to obtain only one of the “approved certifications”; for his or her IA category or specialty and level to meet the minimum requirement. For example, an individual in an IAT Level II position could obtain any one of the four certifications listed in the IAT Level II cell.

Higher level IAT and IAM certifications satisfy lower level requirements. Certifications listed in Level II or III cells can be used to qualify for Level I. However, Level I certifications cannot be used for Level II or III unless the certification is also listed in the Level II or III cell. For example:

The A+ or Network+ certification qualify only for Technical Level I and cannot be used for Technical Level II positions.

The System Security Certified Practitioner (SSCP) certification qualifies for both Technical Level I and Technical Level II. If the individual holding this certification moved from an IAT Level I to an IAT Level II position, he or she would not have to take a new certification.

Higher level CCSP and IASAE certifications do not satisfy lower level requirements

1. This category is equivalent to the CND-SP CATEGORY cited in the DoD 8570.01-M. The name was changed from CND-SP to CSSP to reflect current terminology in the DoD Instruction 8530.01 “Cybersecurity Activities Support to DoD Information Network Operations.

2. CCNA-Security was retired by Cisco, modified, and rebranded as simply “CCNA.” If you possessed the CCNA-Security and were in a position that required that certification when it was retired, you may be eligible for a waiver to cite the rebranded CCNA as a qualifying baseline certification. See the DoD CIO CCNA Security Waiver on the DoD Cyber Workforce Documents website for additional information.

** CySA+ is a CompTIA certification formerly listed as CSA+. The exam and the official name of the certification remain the same, only the acronym has changed.

A+ CE

CCNA-Security

CND

Network+ CE SSCP CCNA-Security CySA+ **

GICSP

GSEC

Security+ CE

CND

SSCP CASP+ CE

CCNP Security

CISA

CISSP (or Associate)

GCED

GCIH

CCSP

IAM Level IIAM Level IIIAM Level III
CAP

CND

Cloud+

GSLC

Security+ CE

HCISPP CAP

CASP+ CE

CISM

CISSP (or Associate)

GSLC

CCISO

HCISPP CISM

CISSP (or Associate)

GSLC

CCISO

IASAE IIASAE IIIASAE III
CASP+ CE

CISSP (or Associate)

CSSLP CASP+ CE

CISSP (or Associate)

CSSLP CISSP-ISSAP

CISSP-ISSEP

CCSP

CSSP Analyst1, 2CSSP Infrastructure Support1CSSP Incident Responder1, 2
CEH

CFR

CCNA Cyber Ops CCNA-Security CySA+ **

GCIA

GCIH

GICSP

Cloud+

SCYBER

PenTest+ CEH CySA+ **

GICSP

SSCP

CHFI

CFR

Cloud+

CND CEH

CFR

CCNA Cyber Ops CCNA-Security

CHFI

CySA+ **

GCFA

GCIH

SCYBER

PenTest+

CSSP Auditor1CSSP Manager1
CEH

CySA+ **

CISA

GSNA

CFR

PenTest CISM

CISSP-ISSMP

CCISO

File details come from the government source that posted it. Updated .