RFI Attachment 4-Draft_IA-RMF-IDIQ_Labor Categories_V1_04-17-23.xlsx
XLSX spreadsheet 30 KB Posted
- Attached to
- USCG Information Assurance (IA) Risk Management Framework (RMF) Services Federal contract opportunity
- Solicitation number
- 70Z04423IESDIAB01
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI Vendor Question-Comment Summary - IA RMF RFI - v08-10-23.xlsx | XLSX spreadsheet | |
| RFI Attachment 6-Question-Comment Form - v1_05-22-23.xls | XLS spreadsheet | |
| RFI Attachment 3-Draft_IA-RMF-IDIQ_Scope of Work_20230525_v2.0.4.docx | DOCX document | |
| RFI Attachment 1-Questionaire_RFI ESDIAB01_05-25-23.docx | DOCX document | |
| RFI Attachment 2 - Draft_IA-RMF-IDIQ_RFP_v4_05-22-23.docx | DOCX document | |
| RFI Attachment 5-Draft_IA-RMF_C5ISCTaskOrderPWS_v0.3_05-25-23.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Labor Categories
| Labor Category | Labor Category Description | Level | Minimum Years Experience | Minimum Experience | Minimum Education/Training | Minimum Certification | DoD Cyber Workforce Framework | Work Role ID |
| Program Manager | Serves as the contract manager and administrator over the entire contract effort including IDIQ and task/delivery orders. Acts as the primary interface and point of contact with Government program authorities and representatives on technical and contract administration issues. Manages contract support operations involving personnel at diverse locations. Organizes, directs, and coordinates planning and production of all contract support activities. Must have demonstrated communications skills with all levels of management. Interfaces with Government managers including the Contracting Officers and the Contracting Officer's Representatives (COR). Under stringent timeframes, assembles and recruits personnel necessary to perform assigned tasks. Establishes and alters (as necessary) management structure to effectively direct contract support activities. Assigns, schedules, and reviews work of subordinates. Ensures conformance to contract and task order specifications and contract provisions. Interprets policies, purposes, and goals of the organization for subordinates. Must be capable of negotiating and making binding decisions for the company. Supervises program operations by developing management procedures, planning and directing program execution, monitoring and reporting progress. Manages and controls financial and administrative aspects of the program with respect to contract requirements. | IV | 10 | Demonstrated capability in managing multitask contracts and/or subcontracts of various types and complexity; expertise in the management and control of funds and resources; demonstrated information technology expertise and communications skills to be able interface with all levels of management. | Bachelor's degree in Computer Science, Information Systems, Engineering, Business, or other related discipline | PMP, IAM II | Program Manager | 801 |
| III | 7 | |||||||
| II | 5 | |||||||
| I | 3 |
| Project Manager | Serves as the central point of contact for task/delivery orders and interfaces with the Contracting Officers Representatives for tasks. Establishes and enforces procedures to assure that all tasks are performed in accordance with applicable standards and quality requirements. Assigns duties and reviews work of subordinates and subcontractors. Meets and confers with CG management officials regarding status of specific technical activities and progress. Resolves problems, issues or conflicts as required, and ensures that program schedules, performances, and deliverables are met. | III | 7 | Demonstrated information technology expertise and direct hands-on experience in the areas of Information Assurance, Cybersecurity, and project management; demonstrated communication skills to be able to interface with all levels of management; strong project management skills in addition to interpersonal, writing, and presentation skills; experience supervising and managing projects of at least 15 personnel, subordinate groups, and diverse locations. | Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related discipline | PMP, IAM II | IT Project Manager | 802 |
| II | 5 | |||||||
| I | 3 |
| Program Analyst | Possess demonstrated knowledge and experience applying methodologies and principles to address client needs. Applies analytic techniques in the evaluation of task objectives and contributes to the implementation of strategic direction. Performs analyst functions including data gathering, interviewing, data modeling, testing, and creation of performance measurement to support objectives. Conducts activities in support of project team's objectives. Works closely with other members of the project team. | III | 7 | Demonstrated experience supporting the implementation of the DIACAP, RMF, DCIS 6/3, NIST, ICD 505, and DODIIS requirements; demonstrated experience in analyzing and preparing program documents and reports; knowledge and capability in developing program requirements, documentation, financial, and/or technical requirements; strong writing and presentation skills; demonstrated communication skills to interface with all levels of management. | Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related discipline | IAM II | IT Program Auditor | 805 |
| II | 5 | |||||||
| I | 3 |
| Security Control Assessor | Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls | III | 6 | Demonstrated experience in determining how a security system should work including its resilience an dependability capabilities. Demonstrated experience in discerning the protection needs of information systems, networks, and platform information technology. Demonstrated experience in applying the principles of confidentiality, integrity, and availability. | Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related discipline | IAM II | Security Control Assessor | 612 |
| II | 4 | |||||||
| I | 2 |
| Information System Security Officer | Analyzes and defines security requirements. Performs risk analysis and security contol assessment and audit services, develops analytical reports as required. May be required to perform or assist in one or more of the following areas: Risk and Vulnerability Assessments; Cyber Hunting activities; conducting Penetration Testing and scanning; assessment of system security for compliance of applications; security of computer network hardware; operating system utility/support software; disaster recovery; incident response and digital forensics; application assessment; vulnerability threat management; cloud security; contingency planning; social engineering; and the development of security policies and procedures. Possess and apply expertise on multiple complex work assignments. | III | 6 | Demonstrated experience in discerning the protection needs of information systems, networks, and platform information technology. Demonstrated experience in applying the principles of confidentiality, integrity, and availability. Demonstrated experience implementing the RMF process especially for system categorization and control selection, implementation, and assessment, as well as continuous monitoring. | Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related discipline | IAM II | Dependent upon Task Order role requirements | TBD |
| II | 4 | |||||||
| I | 2 |
| Information System Security Engineer | Provides technical input, recommendations, and assistance with the implementation of both higher and granular-level cyber security approaches, methods and solutions that incorporate and maintain compliance to requirements resulting from laws, regulations, and other pertinent guidance. | III | 7 | Demonstrated experience in | |
| Information Security (INFOSEC); computer security; cryptography; network security; assessment and authorization; incident response investigations; risk analysis; threat and vulnerability scanning, analysis, and management. Demonstrated experince with system and security engineering principles such as secure architecture, design, and development, and defense in depth. Demonstrated communication skills to interface with all levels of management, as well as appropriate use of style and language for audience. | Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related discipline | IAT II | Dependent upon Task Order role requirements | TBD | |
| II | 5 | ||||
| I | 3 |
| Database Specialist | Administer databases and/or data management systems that allow for the storage, query, and utilization of data | III | 6 | Demonstrated experience in establishing data security controls, maintaining databases, and optimizing database performance. | Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related discipline | IAT I, Computing Environment Certification | Database Administrator | 421 |
| II | 4 | |||||||
| I | 2 |
| Data Analyst | Analyzes and interprets data from multiple disparate sources and builds visualizations and dashboards to report insights. | III | 6 | Demonstrated experience in the following areas: conducting queries and developing algorityms to analyze data structures; generating queries and reports; identifying data patterns/relationships; statistics and associated techniques; use of data analysis tools and writing scripts. Demonstrated communications skills to interface with all levels of management. Strong interpersonal skills to include approachability, effective listening, and appropriate use of style and language for the audience. | Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or other related discipline | IAT II | Data Analyst | 422 |
| II | 4 | |||||||
| I | 2 |
Core Reqmts for ALL Roles
| Core Requirements |
| Knowledge of risk management processes (e.g., methods for assessing and mitigating risk). |
| Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity. |
| Knowledge of cybersecurity principles. |
| Knowledge of cyber threats and vulnerabilities. |
| Knowledge of computer networking concepts and protocols, and network security methodologies. |
| Knowledge of specific operational impacts of cybersecurity lapses. |
| Knowledge of cloud computing service models Software as Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS). |
| Knowledge of cloud computing deployment models in private, public, and hybrid environments and the difference between on-premises and off-premises environments. |
Substitution Tables
| Because of the specialized skills required for highly adaptive cybersecurity work, experience is often substituted for degree or degree for experience as shown in the substitution table. | Level Comparison | |||||
| Degree Substitution Table | Level Indicator | Also Know As | ||||
| Degree | Related Work Experience Substitution | Related Degree and Experience Substitution | Level IV | Senior | ||
| Associate's | 2 year’s work experience may be | |||||
| substituted for an Associate’s Degree | 2 year’s work experience may be | |||||
| substituted for an Associate’s Degree | Level III | Senior or SME | ||||
| Bachelor's | 4 year’s work experience may be substituted for a Bachelor’s Degree | Associate’s Degree plus 2 years work experience may be substituted for a | ||||
| Bachelor’s Degree | Level II | Journeyman or Mid | ||||
| Master's | 6 year’s work experience may be substituted for a Master’s Degree | Bachelor’s Degree plus 2 years work experience may be substituted for a Master’s Degree | Level I | Junior | ||
| Doctorate | 10 year’s work experience may be substituted for a Doctorate Degree | Bachelor’s Degree plus 6 years work experience, or a Master’s Degree plus 4 years work experience may be |
substituted for a Doctorate
Baseline Certifications Approved Baseline Certifications Reference Site: https://public.cyber.mil/cw/cwmp/dod-approved-8570-baseline-certifications/ Date: November 17, 2022
IAT Level I2 IAT Level II2 IAT Level III This table provides a list of DoD approved IA baseline certifications aligned to each category and level of the IA Workforce. Personnel performing IA functions must obtain one of the certifications required for their position, category/specialty and level to fulfill the IA baseline certification requirement. Most IA levels within a category or specialty have more than one approved certification and a certification may apply to more than one level.
An individual needs to obtain only one of the “approved certifications”; for his or her IA category or specialty and level to meet the minimum requirement. For example, an individual in an IAT Level II position could obtain any one of the four certifications listed in the IAT Level II cell.
Higher level IAT and IAM certifications satisfy lower level requirements. Certifications listed in Level II or III cells can be used to qualify for Level I. However, Level I certifications cannot be used for Level II or III unless the certification is also listed in the Level II or III cell. For example:
The A+ or Network+ certification qualify only for Technical Level I and cannot be used for Technical Level II positions.
The System Security Certified Practitioner (SSCP) certification qualifies for both Technical Level I and Technical Level II. If the individual holding this certification moved from an IAT Level I to an IAT Level II position, he or she would not have to take a new certification.
Higher level CCSP and IASAE certifications do not satisfy lower level requirements
1. This category is equivalent to the CND-SP CATEGORY cited in the DoD 8570.01-M. The name was changed from CND-SP to CSSP to reflect current terminology in the DoD Instruction 8530.01 “Cybersecurity Activities Support to DoD Information Network Operations.
2. CCNA-Security was retired by Cisco, modified, and rebranded as simply “CCNA.” If you possessed the CCNA-Security and were in a position that required that certification when it was retired, you may be eligible for a waiver to cite the rebranded CCNA as a qualifying baseline certification. See the DoD CIO CCNA Security Waiver on the DoD Cyber Workforce Documents website for additional information.
** CySA+ is a CompTIA certification formerly listed as CSA+. The exam and the official name of the certification remain the same, only the acronym has changed.
A+ CE
CCNA-Security
CND
Network+ CE SSCP CCNA-Security CySA+ **
GICSP
GSEC
Security+ CE
CND
SSCP CASP+ CE
CCNP Security
CISA
CISSP (or Associate)
GCED
GCIH
CCSP
| IAM Level I | IAM Level II | IAM Level III |
| CAP |
CND
Cloud+
GSLC
Security+ CE
HCISPP CAP
CASP+ CE
CISM
CISSP (or Associate)
GSLC
CCISO
HCISPP CISM
CISSP (or Associate)
GSLC
CCISO
| IASAE I | IASAE II | IASAE III |
| CASP+ CE |
CISSP (or Associate)
CSSLP CASP+ CE
CISSP (or Associate)
CSSLP CISSP-ISSAP
CISSP-ISSEP
CCSP
| CSSP Analyst1, 2 | CSSP Infrastructure Support1 | CSSP Incident Responder1, 2 |
| CEH |
CFR
CCNA Cyber Ops CCNA-Security CySA+ **
GCIA
GCIH
GICSP
Cloud+
SCYBER
PenTest+ CEH CySA+ **
GICSP
SSCP
CHFI
CFR
Cloud+
CND CEH
CFR
CCNA Cyber Ops CCNA-Security
CHFI
CySA+ **
GCFA
GCIH
SCYBER
PenTest+
| CSSP Auditor1 | CSSP Manager1 |
| CEH |
CySA+ **
CISA
GSNA
CFR
PenTest CISM
CISSP-ISSMP
CCISO
File details come from the government source that posted it. Updated .