RFP Attachment 1 - IA RMF IDIQ Scope of Work__v3-3_04-16-24.pdf
PDF 449 KB Posted
- Attached to
- USCG Information Assurance (IA) Risk Management Framework (RMF) Support Services Federal contract opportunity
- Solicitation number
- 70Z04424RESDIAB01
About this file
This document is an Indefinite Delivery Indefinite Quantity (IDIQ) Scope of Work for Information Assurance (IA) Risk Management Framework (RMF) support services for the United States Coast Guard (USCG). The contractor will provide ISSO, ISSE, SCA, and cybersecurity compliance services to support the USCG's implementation of the NIST RMF for all USCG information systems, including those on the NIPRNet, SIPRNet, commercial cloud, and off-network systems. The services cover the full RMF lifecycle from categorization through continuous monitoring. The contract has a 60-month ordering period and work will primarily be performed on-site at USCG facilities, but may also require travel. This is a 100% competitive 8(a) set-aside acquisition with a NAICS code of 541519 and a $34M size standard.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| IA-RMF_RFP-70Z04424RESDIAB01_v18_06-03-2024.pdf | ||
| SF-30_0004_RMF RFP 70Z04424RESDIAB01.pdf | ||
| 0004 Questions - RFP 70Z04424RESDIAB01_06-03-2024.xlsx | XLSX spreadsheet | |
| RFP Attachment 1 - IA RMF IDIQ Scope of Work__v3-4_06-03-2024.pdf | ||
| SF-30_0003_RMF RFP 70Z04424RESDIAB01.pdf | ||
| SF-30_0002_RMF RFP 70Z04424RESDIAB01.pdf | ||
| SF-30_0001_RMF RFP 70Z04424RESDIAB01.pdf | ||
| IA-RMF_RFP-70Z04424RESDIAB01_v17_04-16-2024.pdf | ||
| RFP Exhibit 2 - Question and Answer Form - v1_04-16-2024.xls | XLS spreadsheet | |
| RFP Attachment 2 - IA RMF IDIQ Labor Categories_v1_04-16-2024.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 1 to RFP 70Z04424RESDIAB01
Scope of Work – RMF Support Services v3.3, 16 April 2024 PAGE 1/26
SCOPE OF WORK
FOR
INFORMATION ASSURANCE (IA) RISK MANAGEMENT FRAMEWORK (RMF)
SUPPORT SERVICES
16 April 2024 Version 3.3 v3.3, 16 April 2024 PAGE 2/26
1.0 GENERAL
1.1 BACKGROUND
The United States Coast Guard (USCG) depends on information systems to carry out their missions and business functions in support of six major operational mission programs: Maritime Law Enforcement, Maritime Response, Maritime Prevention, Marine Transportation System Management, Maritime Security Operations, and Defense Operations. An “information system” is a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information [44 USC 3502].
The USCG further categorizes “information system” by type, such as Platform Information Technology (PIT), PIT System, and Operational Technology (OT). Examples of USCG information systems include, but are not limited to computing systems; cyber-physical systems; industrial/process control systems;
environmental control systems; Supervisory Control and Data Acquisition (SCADA); Programmable Logic Controllers (PLC); weapons systems; command, control, communications, intelligence, surveillance, reconnaissance, and navigation systems; motor/engine controls; power generation systems; power distribution systems; propulsion control systems; devices and information technology products such as smart phones and tablets; and embedded devices/sensors. For the purposes of this document, the term “information system” or “system” refers to any type categorization descriptor used in practice by the USCG, and includes systems connected to the Non-Classified Internet Protocol Router Network (NIPRNet), Secret Internet Protocol Router Network (SIPRNet), systems deployed in commercial cloud environments, and off-network systems.
“Cybersecurity” (which replaced the term Information Assurance [IA]) is defined as prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation.
The National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37, Risk Management Framework (RMF) for Information Systems and Organizations, provides a system lifecycle approach for security and privacy, and is integral to the implementation of the Federal Information Security Modernization Act (2014). The RMF is mandatory for federal government use, and promotes near real-time risk management and ongoing information system authorization through the implementation of continuous monitoring processes; provides senior leaders the necessary information to make cost-effective, risk-based decisions with regard to the information systems supporting their core missions and business functions; and integrates cybersecurity into the enterprise architecture and system development life cycle.
The seven-step process of the RMF includes preparation, categorization, selection, implementation, assessment, authorization, and monitoring.
The USCG requires contractor support to perform the RMF tasks that are the responsibility of the Information System Security Officer, Information System Security Engineer, and the Security Control Assessor roles. These roles are defined in Section 2.1 Qualified Personnel. The services provided by these roles, to also include cybersecurity compliance assessment, management, and reporting for USCG systems, are required to properly implement the RMF in alignment with the USCG processes and are applicable to the system from time of acquisition through decommissioning and disposal.
https://www.govinfo.gov/content/pkg/USCODE-2020-title44/pdf/USCODE-2020-title44-chap35-subchapI-sec3502.pdf v3.3, 16 April 2024 PAGE 3/26
1.2 SCOPE
This Indefinite Delivery Indefinite Quantity (IDIQ) contract is established for Contractor provided cybersecurity Risk Management Framework (RMF) services for USCG systems. All effort will be performed at the Individual task order level and will be issued on a Firm-Fixed Price (FFP) basis. During performance of the IDIQ contract, the Contractor must provide the USCG with RMF support aligned with, but not limited to, the cybersecurity roles described below.
The Contractor must provide Information System Security Officer (ISSO) and Alternate ISSO (AISSO) services, Information System Security Engineer (ISSE) services, Security Control Assessor (SCA) services, and Cybersecurity Compliance and Readiness Services as described below to meet the requirements of the USCG Cybersecurity RMF process and cybersecurity of USCG Information Systems. The Contractor must furnish all the necessary personnel, materials, equipment, facilities, travel and other services required to satisfy all task order requirements unless otherwise specified.
1.2.1 Task Area One: Information System Security Officer (ISSO) Services
(a) Serve as the designated ISSO for assigned systems.
(b) Lead the RMF process for assigned programs, organizations, systems, or enclaves.
(c) Generate as appropriate, or gather, assess, and maintain the RMF documentation package that meets all Department of Defense (DoD) requirements and is tailored to a specific system.
Documentation may include but is not limited to: Security Categorization Determination, Implementation Plan, System Security Plan (SSP), Configuration Management Plan (CMP), Incident Response Plans (IRP), Contingency Plans (CP), Authorization documentation, IT Security Plans of Action & Milestones (POA&Ms), Scorecards, Security Assessment Reports (SAR), Continuous Monitoring Strategy, Vulnerability Scans, Hardware/Software lists, Threat Models, Cybersecurity Strategy, Network Topology, Network Cybersecurity Boundary Diagrams, and Data Flow Diagrams using Government prescribed tracking and processing tools.
(d) Ensure that all DoD Information System (IS) cybersecurity-related documentation is current and accessible to properly authorized individuals.
(e) Interpret system designs and diagrams for the purposes of identifying data interconnections, interfaces, protocols, and data types in order to select appropriate controls to remediate or minimize Cybersecurity risk exposure to the Coast Guard.
(f) Provide support and develop a connection approval package such as an Interconnection Security Agreement (ISA), Memorandum of Understanding (MOU), Service Level Agreement (SLA), and so forth, for systems that require connectivity to any type of USCG Local Area Network (LAN) (i.e. DoD Information Network (DoDIN), CGOne, SIPRNet).
(g) Develop plans and perform testing and control assessments to evaluate compliance with all applicable DoD and industry security requirements, standards, and best practices.
(h) Utilize Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)/Secure Requirements Guide (SRG) assessments, including leveraging automation as much as possible to gain efficiencies.
(i) Perform Security Readiness Reviews (SRR) for the Operating Systems and applications.
(j) Review and analyze automated scans produced by Security Compliance Checker (SCC) DISA
Security Content Automation Protocol (SCAP) benchmarks or current DoD approved tools.
(k) Review and analyze automated scans produced by the Assured Compliance Assessment Solution
(ACAS)/Nessus or current DoD and Department of Homeland Security (DHS) approved tools.
(l) Maintain the continuous monitoring process and ensure all systems are compliant with DoD and
USCG security guidelines, and DISA STIGs.
v3.3, 16 April 2024 PAGE 4/26
(m) Maintain process and procedures, in coordination with the Government, that enable the organization to adhere to Requests for Modification (RFM) while remaining compliant with the overall RFM organizational process.
(n) Participate in system change management boards/reviews, as necessary.
(o) Conduct Security Impact Assessments (SIA) as part of the RFM process to determine if there are any impacts to implemented security and privacy controls.
(p) Ensure that all Assessment and Authorization (A&A) packages are completed and submitted in time to prevent Authorization To Operate (ATO) expiration.
(q) Initiate protective or corrective measures when a cybersecurity incident or vulnerability is discovered, and ensure that a process is in place for authorized users to report all cybersecurity-related events and potential threats and vulnerabilities to the ISSO.
(r) Review, update and publish all cybersecurity artifacts to support unclassified (including Chief Financial Officer (CFO)) and classified cybersecurity efforts within USCG prescribed tools and maintain any security relevant artifacts.
(s) During all DHS Systems Engineering Life Cycle (SELC) phases, develop documentation and provide any required information for all levels of classification in support of the A&A process.
(t) Provide support and collaboration to external inspections, evaluations, audits, and assessments as applicable for supported systems.
(u) Manage and track all POA&Ms for assigned systems to address identified weaknesses, vulnerabilities, and audit/assessment findings from creation to closure. Coordinate with other stakeholders as needed in the processing and management of the POA&Ms. This includes validating POA&M content submitted by the area of responsibility (AOR) for weakness remediation; ensuring POA&Ms are submitted via proper channels; providing reports and status tracking of remediation efforts; working with the AOR as needed to ensure items are completed in a timely manner and to gather appropriate artifacts for closure; and identifying POA&Ms that will need waivers or risk acceptance.
(v) Develop and coordinate Contingency Plan (CP) training/testing as required by DoD and USCG policy annually on or before the expiration date of the previous annual test.
(w) Coordinate annual Disaster Recovery (DR) Failover testing for systems with a DR presence and document results of testing to present to the Government as needed.
(x) Maintain Host Based Security System (HBSS) compliance for assigned systems.
(y) Review exception and exclusion requests and provide recommendation for Government approval.
(z) Monitor and remediate rogue devices.
(aa) Review system HBSS reports.
(bb) Review applicable system logs in accordance with USCG or DoD security policies and security configuration guidance.
(cc) Request system-related audit triggers to monitor and correlate daily records at least once per week.
(dd) Review system audit records and intrusion detection data to assist in identifying security incidents.
(ee) Analyze any potential threat vectors across disparate internal related systems.
(ff) Coordinate any security incident forensic analysis with Coast Guard Cyber Command (CGCyber)
Cyber Security Operations Center (CSOC) Incident Response Service Line.
(gg) Report any system related log data integrity issues or gaps to the Government.
v3.3, 16 April 2024 PAGE 5/26
1.2.2 Task Area Two: Information Systems Security Engineer (ISSE) Services
(a) Serve as the Information Systems Security Engineer (ISSE) providing technical input, recommendations, and assistance with the implementation of both higher and granular-level cyber security approaches, methods and solutions that incorporate and maintain compliance to requirements resulting from laws, regulations, and other pertinent guidance.
(b) Participate in acquisition meetings (PMR, PDR, CDR, etc.), concept of operation (CONOP) working groups, change boards, technical exchange meetings and other similar activities.
(c) Design and develop security requirements that drive down risk while maintaining operational capability.
(d) Work between architecture-level and implementation-level engineering meetings to maintain a system-wide view of security functions and apply risk mitigation strategies at the appropriate level.
(e) Provide guidance on work against program requirements and goals. This includes participating in technical discussions, trade studies and working groups, and conducting research on industry best practices for potential implementation.
(f) Interface with various Government stakeholders to explain security requirements, risks and mitigations relative to their priorities of cost and schedule to ensure an acceptable risk tolerance.
(g) Evaluate newly identified threats and vulnerabilities to customer information systems to ascertain the need for additional safeguards and develop timely implementation strategies to reduce risk.
(h) Enforce the design and implementation of trusted relationships among external systems and architectures.
(i) Assess proposed changes to customer information systems, their operation environment, and mission needs for impacts to cybersecurity architectures and continued compliance with cybersecurity requirements.
(j) Provide inputs to development teams responsible for designing and developing organizational information systems and upgrading legacy systems.
(k) Employ best practices when implementing security requirements for information systems including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques.
(l) Keep abreast of current and new security technologies and threats to better support the customer in maintaining cybersecurity resilience.
(m) Identify integration issues related to the implementation of new systems within the existing infrastructure; recommend mitigation and/or resolution options as appropriate.
(n) Assist in the design of systems and networks that encompass multiple enclaves to include those with differing data protection/classification requirements.
(o) Provide assessments of USCG Command, Control, Communications, Computers, Cyber, Intelligence, Surveillance, and Reconnaissance (C5ISR) deliverables for purposes of providing Independent Verification and Validation (IV&V) for all USCG Acquisition Programs. Support will include metrics that provide detailed data on independent assessment of technical feasibility;
cost and schedule reasonableness; review of deliverable documents; and assessment of requirements, architecture and standards in deliverable documents and products.
(p) Support DevSecOps activities as required for sustainment of cybersecurity dashboards, and providing guidance on vulnerability guardrails/thresholds for applications.
v3.3, 16 April 2024 PAGE 6/26
1.2.3 Task Area Three: Security Control Assessor (SCA) Support Services
(a) Support the development, and review of any plan that includes control assessment and implementation including Security Assessment Plans, System Security Plans, and any other security-developed document referring to security and/or privacy controls.
(b) Assess the security and privacy controls in accordance with the assessment procedures defined in the security assessment plan.
(c) Prepare the security assessment report documenting the issues, findings, and recommendations from the control assessment.
(d) Assess a selected subset of the technical, management, and operational controls employed within and inherited by the information system in accordance with the organization-defined monitoring strategy.
(e) Review, validate, and develop RMF authorization recommendations for USCG information systems to be submitted to the Authorizing Official.
(f) Provide a summary of failed controls in Risk Assessment tab in eMASS.
(g) Recommend updates to the POA&M based on the assessment results.
(h) Provide traceability of all vulnerabilities from raw assessment results to the POA&M.
(i) Prepare and submit the Security Authorization Package with program assistance.
(j) Recommend policies and procedures to meet control requirements.
(k) Brief branch, division and department heads on the status of current and future validation efforts.
(l) Support the continuous monitoring program as necessary.
1.2.4 Task Area Four: Cybersecurity Compliance and Readiness Services
1.2.4.1 General
(a) Participate as directed in Integrated Process Teams (IPTs), Design Reviews, and Working Groups to provide input on system security risks, independent cost estimates, cross-classification boundary security technologies, Platform IT packages, and other considerations which may either promote or hinder certification of new systems.
(b) Provide assistance with the destruction of removable media.
(c) Support Cybersecurity strategic planning activities to evaluate enterprise services through the assessment of priorities and risks.
(d) Clearly articulate complex cybersecurity data to a wide variety of Government audiences using strong oral and written communication skills.
1.2.4.2 Scanning and Vulnerability Management
(a) Review all vulnerabilities identified through regularly scheduled and ad-hoc scanning, assign and track remediation responsibility, and track identified vulnerabilities through remediation via the regular patching cycles or until a POA&M is created for tracking.
(b) Identify any vulnerabilities that remain on the system after a period of time and notify designated patch manager to engage to determine how the finding will be disposed.
(c) Coordinate and maintain the DHS and DOD vulnerability database accounts.
(d) Coordinate with ISSOs to advise and facilitate resolution of all Cybersecurity and Information
Security (INFOSEC) issues.
(e) Conduct and evaluate vulnerability scans, including Information Assurance Vulnerability
Management (IAVM) compliance, using USCG prescribed tools recurring by the end of each month, and as necessary as directed by the Government.
v3.3, 16 April 2024 PAGE 7/26
(f) Develop and maintain procedures to track IAVM compliance, and remediation responsibilities (e.g., patching oversight) for future POA&M development.
(g) Utilize standard software tools to conduct vulnerability scans of networks and databases.
(h) Conduct ad hoc remediation vulnerability and compliance scans.
(i) Ensure that 95% authenticated ACAS vulnerability scan rate is achieved and maintained.
(j) Coordinate services with CG Cyber Command’s Enterprise Scanning Team (EST) to ensure service levels are maintained and available.
(k) Ensure that all assets within scanning tools are assigned to the appropriate boundaries to ensure that complete and accurate scanning is occurring.
(l) Provide scan results to the ISSO’s and AISSO’s, as well as information system administrators.
(m) Manage and coordinate scanning credentials to ensure all environments are accessible by the scanners and sensors.
(n) Provide false-positive (FP) management ensuring there is a means to submit a FP claim, process that claim through proper validation, and coordinate with CGCYBER for submission of DISA tickets if warranted. Prevent the FPs from continuously being analyzed but be able to revalidate and dispose of periodically.
1.2.4.3 Knowledge and Metrics Management
(a) Develop and maintain metrics to track and analyze trends in cybersecurity readiness and compliance.
(b) Utilize tools and tracking mechanisms that must automate reporting and data collection of INFOSEC associated vulnerabilities.
(c) Collaborate with the Government to develop metrics to provide the Cyber Health for information systems based on mandated reporting and supplemental risk scorecards.
(d) Track and report status on all official authoritative orders. These orders can originate from JFHQ-DoDIN, US Cyber Command, CG Cyber Command, and generally take the form of Operational Orders (OPORDs), Task Orders (TASKORDs), Fragmentation Orders (FRAGOs) applicable to released TASKORDs or OPORDs, All Coast Guard Messages (ALCOASTs) or Time Compliant Technical Orders (TCTOs).
(e) Maintain awareness of all policies that provide input to cybersecurity requirements and facilitates standards and guidance distribution and updates to cybersecurity stakeholders.
(f) Respond to ad-hoc cybersecurity data calls as directed by the Government.
(g) As security requirements change, assist in preparation, review, and update policies and procedures for compliance with DHS, DoD and USCG requirements.
(h) Provide data analysis, metrics development, and reporting for cybersecurity areas such as
Inventory and Asset Management, Vulnerability remediation AORs, IAVM tracking, and so forth.
1.2.4.4 Command Cyber Readiness Inspection (CCRI) Support
Provide support to Scheduled and Limited Notice (LN) Command Cyber Readiness Inspections. This support coverage includes all C5I systems/assets within scope of the particular CCRI and may include traveling to sites scheduled for inspections to aid as needed. Areas of support include, but are not limited to:
(a) Site Scoping.
(b) Vulnerability Per Host (VPH) Determination.
(c) Artifact Gathering and Staging.
v3.3, 16 April 2024 PAGE 8/26
(d) POA&M Support.
1.2.4.5 Privileged User Account Management
(a) Provide coordination of the USCG Privileged User Management Program (PUMP) process across all applicable staff members at all places of performance.
(b) Ensure compliance with the overall PUMP program administered by the USCG.
(c) Annually verify Admin Access accounts.
1.2.4.6 Cross Domain Analysis and Evaluation
(a) Identify Cross Domain requirements, evaluation of candidate solutions, recommendations for integration approaches including security considerations, generation of documentation for certifications, accreditations, and approvals related to Cross Domain Devices and the facilitation of processing Cross Domain Solution (CDS) tickets.
(b) Provide documentation and analysis support as needed to determine need for High Assurance Guards (HAGs) and Controlled Interface Devices (CIDs) for use on USCG assets.
(c) Provide production, documentation, and development support for the development of Controlled Interface for use on assets to include: Rule Set development; Acknowledge/Not Acknowledge (ACK/NAK) Channel set-up; develop Message Analysis and Generation Tables; engineering support for CDS Controlled Interfaces.
1.3 APPLICABLE DOCUMENTS
The following documents provide mandates, policy, specifications, standards, or guidelines that apply to performing the work described in this document:
Table 1 Applicable Documents
REFERENCE DESCRIPTION / TITLE
FISMA Federal Information System Modernization Act (2014)
P.L. 93-579 Public Law 93-579 Privacy Act, December 1974 (Privacy Act)
EO 13526 Classified National Security Information
32 CFR Part 117 National Industrial Security Program Operating Manual (NISPOM)
OMB A-130 Managing Information as a Strategic Resource
OMB M-05-22 Transition Planning for Internet Protocol Version 6 (IPv6)
OMB M-19-03 Management of High Value Assets
CJCSI 6510.01E Information Assurance and Support To Computer Network Defense
DoDD 8140.01 Cyberspace Workforce Management
DoDM 8140.03 Cyberspace Workforce Qualification and Management Program
DoDI 8500.01 Cybersecurity
DoDI 8510.01 Risk Management Framework for DoD Systems
DHS BOD 18-02 Securing High Value Assets https://www.cisa.gov/federal-information-security-modernization-act https://www.congress.gov/bill/93rd-congress/senate-bill/3418/text/pl?overview=closed https://www.govinfo.gov/content/pkg/CFR-2010-title3-vol1/pdf/CFR-2010-title3-vol1-eo13526.pdf https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-D/part-117 https://www.cio.gov/policies-and-priorities/circular-a-130/ https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/memoranda/2005/m05-22.pdf https://www.cio.gov/policies-and-priorities/management-HVA/ https://www.jcs.mil/Portals/36/Documents/Library/Instructions/6510_01.pdf?ver=2016-02-05-175054-497 https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/814001p.PDF?ver=si7QmZONMCW2tStUt4ws3Q%3d%3d https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/814003p.PDF?ver=Yi_dR4VeVd7-yxrty2REFQ%3d%3d https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pdf?ver=2019-10-07-112048-860 https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001p.pdf?ver=5YnACrAlUCPZ_qeq4T5nlg%3d%3d https://cyber.dhs.gov/assets/report/bod-18-02.pdf v3.3, 16 April 2024 PAGE 9/26
REFERENCE DESCRIPTION / TITLE
DHS MD 103-01 Enterprise Data Management Policy
DHS MD 140-01 Information Technology Security Program
DHS MD 11042.1 Safeguarding Sensitive But Unclassified (FOR OFFICIAL USE ONLY) Information
DHS MD 11056.1 Sensitive Security Information (SSI)
DHS Instruction 102-01-103
Systems Engineering Life Cycle (SELC)
DHS Instruction 102-01-004
Agile Development and Delivery for IT
DHS Policy Directive 4300A
Information Technology System Security Program, Sensitive Systems
OIG-09-65 The DHS Personnel Security Process
COMDTINST
M5000.10 (series)
USCG Major System Acquisition Manual (MSAM)
COMDTINST
M5000.11 (series)
USCG Non-Major System Acquisition Manual (NMAP)
FIPS 199 Federal Information Processing Standards Publication (FIPS) 199 - Standards for Security Categorization of Federal Information and Information Systems
FIPS 200 Minimum Security Requirements for Federal Information and Information Systems
NIST SP 500-267 USGv6 Profile
NIST SP 800-18 Guide for Developing Security Plans for Information Technology Systems
NIST SP 800-30 National Institute of Standards and Technology (NIST) Guide for Conducting Risk Assessments
NIST SP 800-35 Guide to Information Technology Security Services
NIST SP 800-37 Risk Management Framework for Information Systems and Organizations:
A System Life Cycle Approach for Security and Privacy
NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View
NIST SP 800-44 Guidelines on Securing Public Web Servers
NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations
NIST SP 800-53A Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans
NIST SP 800 53B Control Baselines for Information Systems and Organizations https://www.dhs.gov/sites/default/files/publications/mgmt/planning-and-budgeting/mgmt-dir_103-01-enterprise-data-management-policy_revision-01.pdf https://www.dhs.gov/sites/default/files/publications/mgmt/information-and-technology-management/mgmt-dir_140-01-info-tech-security-program_revision-02.pdf https://www.dhs.gov/sites/default/files/publications/Management%20Directive%2011042.1%20Safeguarding%20Sensitive%20But%20Unclassified%20%28For%20Official%20Use%20Only%29%20Information_0.pdf https://www.dhs.gov/sites/default/files/publications/Management%20Directive%2011056.1%20Sensitive%20Security%20Information%20%28SSI%29.pdf https://www.dhs.gov/sites/default/files/publications/Systems%20Engineering%20Life%20Cycle.pdf https://www.dhs.gov/sites/default/files/publications/Systems%20Engineering%20Life%20Cycle.pdf https://www.dhs.gov/sites/default/files/publications/Instruction_102-01-004_Revision_00_Agile_Development_SIGNED_04-11-2016%281%29.pdf https://www.dhs.gov/sites/default/files/publications/Instruction_102-01-004_Revision_00_Agile_Development_SIGNED_04-11-2016%281%29.pdf https://dhsconnect.dhs.gov/org/comp/mgmt/policies/Directives/4300A.pdf https://dhsconnect.dhs.gov/org/comp/mgmt/policies/Directives/4300A.pdf https://www.oig.dhs.gov/sites/default/files/assets/Mgmt/OIG_09-65_May09.pdf https://media.defense.gov/2021/Dec/08/2002905785/-1/-1/0/CIM_5000_10G.PDF https://media.defense.gov/2021/Dec/08/2002905785/-1/-1/0/CIM_5000_10G.PDF https://media.defense.gov/2021/Nov/15/2002892989/-1/-1/0/CIM_5000_11D.PDF https://media.defense.gov/2021/Nov/15/2002892989/-1/-1/0/CIM_5000_11D.PDF https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.199.pdf https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.200.pdf https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.500-267Br1.pdf https://csrc.nist.gov/publications/detail/sp/800-18/rev-1/final https://csrc.nist.gov/publications/sp800 https://csrc.nist.gov/publications/sp800 https://csrc.nist.gov/publications/sp800 https://csrc.nist.gov/publications/sp800 https://csrc.nist.gov/publications/detail/sp/800-44/version-2/final https://csrc.nist.gov/publications/sp800 https://csrc.nist.gov/publications/sp800 v3.3, 16 April 2024 PAGE 10/26
REFERENCE DESCRIPTION / TITLE
NIST SP 800-61 Computer Security Incident Handling Guide
NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response
NIST SP 800-115 Technical Guide to Information Security Testing and Assessment
NIST SP 800-128 Guide for Security-Focused Configuration Management of Information Systems
NIST SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations
NIST SP 800-153 Guidelines for Securing Wireless Local Area Networks (WLANs)
NIST SP 800-160
Vol 1
Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems
NIST SP 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
NIST SP 800-171A Assessing Security Requirements for Controlled Unclassified Information
1.4 IT SERVICE DELIVERY
The Contractor must adopt, apply, and help institutionalize the IT Delivery Standards of the Defense Enterprise Service Management Framework (DESMF) and the TBM value-management framework – informed and enabled by best practices and norms from bodies of knowledge such as the Information Technology Infrastructure Library (ITIL®), Control Objectives for Information and Related Technologies (COBIT®), the Capability Maturity Model Integration (CMMI®), Six Sigma, International Organization for Standardization/ International Electrotechnical Commission (ISO/IEC) 20000, ISO/IEC 27001, and Project Management Institute (PMI) Project Management Body of Knowledge (PMBOK®).
2.0 CONTRACTOR PERSONNEL
2.1 QUALIFIED PERSONNEL
The Contractor must provide qualified personnel to perform all requirements specified in this Scope of Work, including the functional and technical services that are the responsibility of the following USCG roles that are required to support of the DoD RMF process. These roles and responsibilities are defined in NIST SP 800-37 rev. 2, and are listed as System Security/Privacy Officer, System Security/Privacy Engineer, and Control Assessor:
• Information System Security Officer (ISSO) o The ISSO is an individual assigned responsibility for maintaining the appropriate operational security posture for an information system.
• Alternate Information System Security Officer (AISSO) o The AISSO assists in the day-to-day duties required to safeguard the information system as assigned by the ISSO.
• Information System Security Engineer (ISSE) https://csrc.nist.gov/publications/sp800 https://csrc.nist.gov/publications/detail/sp/800-86/final https://csrc.nist.gov/publications/sp800 https://csrc.nist.gov/publications/sp800 https://csrc.nist.gov/publications/sp800 https://csrc.nist.gov/publications/detail/sp/800-153/final https://csrc.nist.gov/publications/detail/sp/800-160/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-160/vol-1-rev-1/final v3.3, 16 April 2024 PAGE 11/26 o The ISSE applies scientific, engineering, and cybersecurity principles to deliver trustworthy systems that satisfy stakeholder requirements with their established risk tolerance.
• Security Control Assessor (SCA) o The SCA is responsible for conducting a comprehensive assessment of implemented security and privacy controls and control enhancements to determine the effectiveness of the controls.
The Cyberspace workforce elements addressed include contractors performing functions in designated Cyber IT positions and Cybersecurity positions. Contractor personnel performing cyberspace work roles are required to be fully qualified by qualification standards and requirements in accordance with DoDD
8140.01 and DoDM 8140.03 prior to accessing DoD information systems. Contractor personnel must be appropriately qualified prior to the start of the contract performance period or before commencement of cyberspace work during the performance period. Waivers and exceptions for Contractor qualifications will not be granted.
Contractors that access USCG IT must also follow USCG Cybersecurity guidelines and provisions and may be required to complete a System Authorization Access Request (SAAR) DD-2875.
2.2 CONTINUITY OF SUPPORT
The Contractor must ensure that the contractually required level of support for this requirement is maintained at all times. The Contractor must ensure that all contract support personnel are present for all hours of the workday. If for any reason the Contractor staffing levels are not maintained due to vacation, leave, appointments, etc., and replacement personnel will not be provided, the Contractor must provide e-mail notification to the Contracting Officer’s Representative (COR) prior to employee absence.
Otherwise, the Contractor must provide a fully qualified replacement.
2.3 KEY PERSONNEL
Key personnel are Contractor personnel in positions that the Government considers to be essential to the performance of this contract. The Government expects immediate notification upon resignation of personnel holding Key positions. Before replacing any individual designated as Key by the Government, the Contractor must notify the Contracting Officer (KO) no less than 15 business days in advance, submit written justification for replacement, and provide the name and qualifications of any proposed substitute(s). All proposed substitutes must possess qualifications equal to or superior to those of the Key person being replaced, unless otherwise approved by the Contracting Officer. The Contractor must not replace Key Contractor personnel without approval from the Contracting Officer. The following Contractor personnel are designated as Key for this requirement. Note: The Government may designate additional or different Contractor personnel as Key at the time of individual task order awards.
• Program Manager
• Task Order Project Manager(s)
2.4 PROGRAM MANAGER
The Program Manager (PgM) must be responsible for all Contractor work performed under this Scope of Work. The Program Manager is the single point of contact for the Contracting Officer and the COR. The name of the Program Manager, and the name(s) of any alternate(s) who will act for the Contractor in the v3.3, 16 April 2024 PAGE 12/26 absence of the Program Manager, must be provided to the Government at the time of contract award. The Program Manager is further designated as Key by the Government. During any absence of the Program Manager, only one alternate must have full authority to act for the Contractor on all matters relating to work performed under this contract. The Program Manager and all designated alternates must be able to read, write, speak and understand English. Additionally, the Contractor must not replace the Program Manager without prior notification to the Contracting Officer.
2.5 PROJECT MANAGER
The Project Manager(s) (PjM) for operations and technical oversight will be responsible for the day-to-day Task Order operations of the contracted functions at all locations covered by a contract task order. This position will be focused on scheduling personnel, staffing levels, providing appropriate measurement criteria on a daily, weekly, monthly, quarterly, and annual basis. This position is responsible for coordinating all aspects of onboarding and departing contractor personnel, including coordinating with the Command/Division Security Office and Property Control Officer. This position will be responsible for ensuring the day-to-day operations are aligned to meet the USCG goals and targets, and for analyzing statistical data to optimize staffing. The Project Manager will be responsible for overseeing the proper operation of Task Order resources including but not limited to the tools used to support the contracted functions. The Project Manager will be responsible for making continuous improvement recommendations to the COR on the operation of the contracted functions.
The Project Manager must be available to the COR via telephone between the hours of 0800 and 1600 EST (UTC -5), Monday through Friday, excluding Federal holidays, and must respond to a request for discussion or resolution of technical problems within 2 hours of notification.
2.6 EMPLOYEE IDENTIFICATION
Contractor employees visiting Government facilities must wear an identification badge that, at a minimum, displays the Contractor name, the employee’s photo, name, clearance-level and badge expiration date.
Visiting Contractor employees must comply with all Government escort rules and requirements. All Contractor employees must identify themselves as Contractors when their status is not readily apparent and display all identification and visitor badges in plain view above the waist at all times.
Contractor employees working on-site at Government facilities must wear a Government issued identification badge. All Contractor employees must identify themselves as Contractors when their status is not readily apparent (in meetings, when answering Government telephones, in e-mail messages, etc.) and display the Government issued badge in plain view above the waist at all times.
2.7 EMPLOYEE CONDUCT
Contractor’s employees must comply with all applicable Government regulations, policies and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting or working at Government facilities. The Contractor must ensure Contractor employees present a professional appearance at all times and that their conduct must not reflect discredit on the United States or the Department of Homeland Security. The Project Manager must ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.
v3.3, 16 April 2024 PAGE 13/26
2.8 REMOVING EMPLOYEES FOR MISCONDUCT OR SECURITY REASONS
The Government may, at its sole discretion (via the Contracting Officer), direct the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons. Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract.
The Contracting Officer will provide the Contractor with a written explanation to support any request to remove an employee.
3.0 OTHER APPLICABLE CONDITIONS
3.1 SECURITY
The performance of this Contract requires the safeguarding of classified and Controlled Unclassified Information (CUI). Contractor employees must safeguard this information against unauthorized disclosure or dissemination.
Classified information is U.S. Government information which requires protection in accordance with Executive Order 13526, “Classified National Security Information,” and supplemental directives. The Contractor must abide by the requirements set forth in DD Form 254, Contract Security Classification and the National Industrial Security Program Operating Manual (NISPOM), 32 CFR Part 117, for protection of classified information as directed by the Federal Acquisition Regulation (FAR) 52.204-2, Security Requirements (Mar 2021). The maximum level for this IDIQ is up to SECRET.
Specific Task Orders will include standard security requirements to access classified related information, along with the associated DD Form 254, as applicable. Access to all classified information is based on a strict need-to-know principle. Contractor personnel will be performing specific classified related tasks based on the stakeholders’ requirements. The Contractor will be required to access classified information, participate in classified meetings, access classified IT/IS, and may include only physical access to classified areas to support specific delivery tasks.
The Contractor’s facility must have a current Facility Clearance (FCL) at the SECRET level for the overall conditions of this Contract at the time of award. Any subcontractors identified for approval must possess a FCL at the appropriate classification to support classified related tasks.
Contractor personnel must possess U.S. Citizenship and must have a current background investigation to obtain a final Personnel Clearance (PCL) at the SECRET level based on mission support. Persons determined by the Government to be a substantial risk to U. S. national security interests will not be employed under the Contract.
Contractor personnel must maintain their security clearance eligibility for the duration of the Contract.
All designated Contractor personnel working this contract must have a Classified Information Non- Disclosure Agreement (SF-312) properly executed by their contracting company’s Facility Security Officer (FSO) and file with their clearance granting authority. There is no requirement for the Contractor to process or store classified information at the company-owned facilities.
The Contractor must provide a Visit Authorization Letter (VAL), equivalent ot the USCG Visit Access Request (VAR), to the place of performance. All requests must contain the information required by the NISPOM and must not exceed the completion date of the contract, or a 12-month period, whichever is https://www.acquisition.gov/far/52.204-2 https://www.acquisition.gov/far/52.204-2 v3.3, 16 April 2024 PAGE 14/26 shorter. Additionally, the VAL must note the applicable Government COR or Technical Assistant (TA) responsible for coordinating the visit so that the host location can verify “Need-to-Know,” as necessary.
Contractors who work in a DHS/USCG installation and/or Government-leased facilities and are embedded or integrated within a program or activity, must report all adverse information, suspicious contacts, and other reportable incidents to the local Command Security office.
Any misconduct/wrongdoing of a Contractor, modification to the contract, or changes to the company ownership status which could have an adverse impact upon national security must be reported immediately by the Contractor to the Contracting Officer or the designated Contracting Officer’s Representative (COR).
Contractor personnel working on-site at Government facilities must comply with all installation security requirements and all security regulations and directives for this Contract.
Contractor performance may require OCONUS support for CG missions. Any travel overseas for classified support must abide by the International Security Requirements as directed within the NISPOM and any additional directives by USCG.
3.1.1 Facility and Computer Access
3.1.1.1 Security Risk and Background Investigation
The requirements office anticipates the following:
Check Applicable
Box
Tier Investigation Risk Form
X 1 Low Risk, Non-Sensitive, Physical/Logical Access (HSPD-12 Credentialing) SF85
2 Moderate Risk, Public Trust SF85P
X 3 Non-Critical Sensitive, L, Confidential and Secret Information SF86
4 High Risk, Public Trust SF85P
5 Q, Top Secret, Compartmented Information, Critical Sensitive, Special Sensitive SF86
All Contractor personnel working under this contract must, at a minimum, have a favorable fingerprint check and have the minimum Tier 1 investigation initiated or completed in order to obtain a DoD Common Access Card (CAC).
The Contractor must require regular physical access to the U.S. Government facilities/IT systems under this acquisition, so Contractor personnel must undergo a security check and obtain a CAC.
Contractors are required to return all CACs to an appropriate CG sponsor representative when no longer performing required contract tasks. This CG sponsor will be their onsite CG supervisor, assigned Mission Partner Identity, Credential and Access Management (MP ICAM) Trusted Agent (TA) or COR. The Prime Contractor must be responsible for ensuring all Contractors (including subcontractors) return each CAC to the proper CG representative.
v3.3, 16 April 2024 PAGE 15/26
3.1.1.2 Mission Partner Identity, Credential and Access Management (MP ICAM)
(a) "Contractor employee" means an employee of a firm, or an individual, under contract or subcontract to the Coast Guard to provide services who also requires one or more of the following:
(1) Physical access to multiple Coast Guard facilities or multiple federally controlled facilities on behalf of the Coast Guard on a recurring basis (a minimum of 2 times per week and/or 8 times per month) for a period of 6 months or more.
(2) Remote access, via logon, to Coast Guard network using Coast Guard-approved remote access procedures.
(3) Both physical access to Coast Guard facility and logical access, via logon, to Coast Guard networks on-site or remotely. Access to the Coast Guard network must require the use of a computer with Government-controlled configuration or use of Coast Guard-approved remote access procedure in accordance with the Defense Information Systems Agency (DISA) Security Technical Implementation Guide.
(b) Homeland Security Presidential Directive (HSPD)-12 mandates a federal standard for secure and reliable forms of identification for federal employees and contractor employees. The Common Access Card (CAC) is a personal identification card for the Department of Defense (DOD)/Uniformed Services and complies with HSPD-12. The Coast Guard has instituted the CAC as its HSPD-12 compliant personal identification card for contractor and subcontractor employees who are required to access a Coast Guard, DOD, or other federally-controlled computer information system and/or facility, or need public key infrastructure (PKI) authentication to perform their contractual duties. The Mission Partner Identity, Credential and Access Management (MP ICAM) is the automated application process for obtaining a CAC.
(c) Contractor and subcontractor employees working pursuant to this contract who are required to access a Coast Guard, DOD, or other federally-controlled computer information system and/or facility, or need PKI authentication to perform their contractual duties must use MP ICAM to obtain a CAC.
(d) The COR or Alternate COR (ACOR) is the MP ICAM Mission Partner Affiliation Sponsor (MPAS) and initiates contractor accounts in the MP ICAM, approving, returning, or rejecting CAC applications (as applicable); re-verifying assigned contractors every six months; revoking contractor and employee eligibility for a CAC.
(e) The MPAS ensures that contractor personnel satisfy the security requirements for CAC issuance prior to creating the CAC application in MP ICAM. Current investigative requirements must be verified according to Commandant Instruction 5500.18. The initial CAC issuance requires a favorably adjudicated Tier 1 investigation (equivalent or higher) or a Tier 1 background investigation (BI) (equivalent or higher) package that has been successfully scheduled with the investigative service provider (ISP) and a FBI fingerprint check with favorable results. The MPAS and Sponsor or other appropriate federal Government representative must coordinate with the unit BI Verifier (Command Security Officer / Mission Partner Affiliation Sponsor Manager) or the U.S. Coast Guard Security (SECCEN) to confirm the appropriate investigation has been favorably adjudicated or scheduled at the ISP with favorable FBI fingerprint results.
(f) The COR or contracting officer (KO) provides such forms to, or requests such information from, v3.3, 16 April 2024 PAGE 16/26 contractor employees that may be necessary for obtaining a CAC via the MP ICAM. The Contractor submits completed forms and information as directed by the COR or KO. Contractors are responsible for the accuracy and completeness of the information submitted and for any liability resulting from the Government's reliance on inaccurate or incomplete information.
(g) Contractor employees who are declined via the MP ICAM are ineligible to perform work under this contract.
(h) When an employee with a CAC is no longer performing work under this contract, the employee must return the CAC to the COR/MPAS or KO on the same day the employee stops working.
(i) The contractor must insert this requirement in all subcontracts when a subcontractor's employee is required to access a Coast Guard, DOD, or other federally-controlled computer information system and/or facility, or need PKI authentication to perform contractual duties.
3.1.2 Special Categories
Actual knowledge of, generation, or production of NATO information is not required for performance on the Contract/task orders. However, Contractor personnel may require an account to access the Secret Internet Protocol Router Network (SIPRNet). Information managed under the “NATO-SECRET” caveat can be accessible via SIPRNet. Contractor personnel will require a NATO security briefing and the requisite security read-on due to NATO information residing on the SIPRNet. The Contractor will not access, download, or further disseminate any special access data (i.e., intelligence, NATO, and so forth) outside the execution of the defined contract requirements. Other classified systems may be required; and must follow guidance of the cognizant agencies.
Contractor personnel requiring SIPRNet access must have a final SECRET clearance to obtain a SIPRNet account.
The Contractor must adhere to the USCG rules and procedures of handling non-SCI material at the USCG Government facility and/or sponsoring agency facility if access is needed to non-SCI.
The Contractor personnel requiring access to non-SCI information must be U. S. citizens; and have been granted at least a Final SECRET personnel clearance by the U. S. Government, prior to being given access to such information released or generated under this Contract.
3.1.3 Contractor Personnel Training
The Contractor must ensure that all Contract employees with security clearances meet the prescribed security training required by the NISPOM.
All Contractors with security clearances must comply with Insider Threat Training requirements per NISPOM.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .