Updated_Attachment__15_Security_Plan_CRN_AMN_RFP-15-100-SOL-00004.pdf

PDF 119 KB Posted

Attached to
BARDA Chem and RadNuc Animal Model Development Federal contract opportunity
Solicitation number
RFP-15-100-SOL-00004
Issued by
Department of Health and Human Services Immediate Office of the Secretary

About this file

Updated Attachment 15 for RFP-15-100-SOL-00004.

View the file

Other files for this federal contract opportunity

Other files attached to BARDA Chem and RadNuc Animal Model Development, newest first.
File Type Posted
Q A_for_RFP-15-100-SOL-00004_4.24.15.pdf PDF
Q A_for_RFP-15-100-SOL-00004_4.21.15.pdf PDF
Q A_for_RFP-15-100-SOL-00004_4.16.15.pdf PDF
CRN_AMN_RFP-15-100-SOL-00004.pdf PDF
CRN_AMN_RFP-15-100-SOL-00004.docx DOCX document
AMENDED__02_Pre_Soliciation_Notice_Animal_Models_RFP_IDIQ.pdf PDF
AMENDED__01_Pre_Soliciation_Notice_Animal_Models_RFP_IDIQ.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT #15

SECURITY PLAN TEMPLATE WITH INSTRUCTIONS

COMPANY SECURITY PLAN TEMPLATE

Prepared by:

Program Protection Office

Office of Biomedical Advanced Research and Development Authority

Preface

Intent; The intent of this document is to provide possible practices and procedures that entities may use to assist them in developing and implementing the written security plan required by the Office of Biomedical Advanced Research and Development Authority (BARDA). The ideas and suggestions provided in this document do not constitute or establish minimum standards but are provided as general guidance. Each security program will be assessed in its totality. This document was prepared as a reference guide and template to assist entities in the development of a site-specific security plan.

Additionally, a BARDA Audit Checklist is provided at Appendix B.

A good security plan model could be to organize into the following sections: Physical Security, Personnel Security, Information Security, Security Awareness Training, Information Technology Security, and Transportation Security (shipping). For each section, we recommend that you provide a complete description of the relevant specific security measures you will use to reduce your vulnerabilities. You should also discuss personnel roles and responsibilities for implementing each measure. There is set formula for what an acceptable security plan looks like. Sometimes very simple changes in procedures can achieve the same result as a much more costly equipment-based solution.

A layered approach to security is recommended when designing an overall security strategy. Security protective measures developed in unison are more cost effective and successful. Each layer alone may be capable of stopping an incident but in combination, their security value is multiplied, creating a much stronger, formidable system. A potential terrorist, criminal, or unauthorized person who has to overcome multiple security layers in order to carry out an attack is more likely to be pre-empted, deterred, or to fail during the attempt. The below illustration depicts the concept of layered security.

General Outline of Security Plan Topics

I. Organization and Responsibilities II. Site- Specific Risk Assessment

a. Statement of Threats

i. Industrial Espionage

ii. Criminal

iii. Terrorism

iv. Natural Disasters

b. Vulnerability + Consequence of Loss=Risk III. Threat Levels

a. Low – Protective Measures

b. Medium – Protective Measures

c. High – Protective Measures

IV. Physical Security

a. General Description

b. Access Control

i. Perimeter

ii. Internal

iii. Badge Policy

1. Permanent employees

2. Visitors

3. Others

c. Parking Areas

d. Security Lighting

e. Other Building Features

f. Signage

g. Designation of Restricted Areas

i. Entry Points

ii. Electronic Access Control

iii. Electronic Intrusion Detection

iv. Closed Circuit Television

v. Other Control Measures

V. Personnel Security Program

a. General Description

b. Recruitment of New Employees

i. Interview process

ii. Background Checks

iii. Suitability / Adjudication Guidelines

iv. Non-Disclosure Agreements

v. Rules of Behavior

vi. Access Determination/Badge System

c. Temporary Employees

i. Interview

ii. Background Checks

iii. Non-Disclosure Agreements

iv. Access Determination/Badge System

d. Contractor Support

e. Termination

i. Denial of Access

ii. Post Employee Interview

iii. Non-Disclosure Agreements

VI. Information Security

a. General Description

b. Identification of Sensitive Information

c. Physical Document Control

i. Marking

ii. Secure Storage

iii. Destruction Policy

d. Information Technology Security

i. General Description

ii. Media Control

1. Media Protection

2. Sanitization and Disposal of Information

3. Input/Output Controls

iii. Equipment

1. Workstations

2. Laptops and Other Portable Computing Devices

iv. Personally Owned Equipment and Software

v. IT Disaster Recovery

1. Backup Data.

2. Store Backup Data

VII. Security Awareness Training and Reporting Requirements

a. Training

i. New Employees

ii. Annual

b. Security Reporting

i. Reporting of Compromise

ii. Reporting of Incidents VIII. Transportation Security

I. Organization and Responsibilities – Provide an overview of key company personnel with security responsibilities. Include an organization chart, key personnel, contact numbers, and areas of expertise.

II. Site Specific Risk Assessment - Provide an assessment of the threat environment and discuss potential hazards that could undermine or hinder completion of the contract. Threats, such as terrorism, industrial espionage/sabotage, may appear to pose a minimal risk to company operations but the possibility of their occurrence and its impact on operations can not be ignored. Additionally, an all-hazards approach should be considered when developing a security strategy. Loss of power, severe weather, and other natural or manmade disasters can be mitigated by thoughtful security and contingency planning. With limited security dollars, each company will design the countermeasures to vulnerabilities to meet its primary security objectives while addressing identified risks.

III. Threat Levels – Institute a graduated Threat Advisory System to advise employees of potential increased threats and to implement a set of corresponding protective measures which would further reduce vulnerability and increase response capability during periods of heightened alert. Threat levels can be as simple as: Low; Medium; High; or something that corresponds with local, state, or federal government procedures. During periods of heightened alert, entities should consider the following no cost / low cost measures:

• Increase the visible security personnel presence wherever possible.

• Rearrange exterior vehicle barriers (if available) to alter traffic patterns near facilities.

• Institute a vehicle inspection program.

• Institute/increase vehicle, foot, and roving security patrols.

• Implement random security guard shift changes.

• Arrange for law enforcement vehicles to be parked randomly near entrances and exits.

• Approach all illegally parked vehicles in and around facilities, question drivers and direct them to move immediately, if owner cannot be identified, have vehicle towed by law enforcement.

• Report any suspicious activity immediately to law enforcement.

• Limit the number of access points and strictly enforce access control procedures.

• Implement stringent identification procedures to include conducting 100% "hands on" checks of security badges for all personnel, if badges are required.

• Remind personnel to properly display badges, if applicable, and enforce visibility.

• Require two forms of photo identification for all visitors.

• X-ray packages and inspect handbags and briefcases at entry if possible.

• Validate vendor lists for all routine deliveries and repair services.

IV. Personnel Security – Provide a detailed description of your Personnel Security Program that includes hiring practices, determination of suitability for employment, termination for cause processes, and individual training goals. Personnel Security focuses on verifying the identity and credentials of a candidate and assessing their trustworthiness based on past behavior. Examples of Personnel Security measures include:

• Conduct national and local criminal history check;

• Confirm past employment (five years);

• Verify education;

• Perform reference checks;

• Perform credit check;

• Confirm Citizenship and Social Security number;

• Conduct drug and alcohol testing;

• Sign non-disclosures agreements.

Entities should also provide a description of methods and practices used to determine suitability for employment. Suitability refers to identifiable character traits and conduct sufficient to decide whether an individual is likely or not likely to be able to carry out the duties of a job with appropriate integrity, efficiency, and effectiveness. When adjudicating suitability, the process should carefully weigh reliable information about the person, past and present, favorable and unfavorable, before reaching a final determination. Consideration should also be given to the following when evaluating a potential employee’s suitability:

• Nature, extent and seriousness of the conduct

• Circumstances surrounding the conduct, to include knowledgeable participation

• Frequency of the conduct

• Individual's age and maturity at the time of the conduct

• Extent to which participation was voluntary

• Presence or absence of rehabilitation and other permanent behavioral changes

• Motivation for the conduct

• Potential for pressure, coercion, exploitation, or duress

• Likelihood of continuation or recurrence.

V. Physical Security – Provide a detailed description of your Physical Security Program designed to prevent or deter attackers from accessing a facility, resource, or information. Physical Security program uses a coordinated approach using obstacles, barriers, equipment, and policies to limit access to company property to only those with a need.

a. Obstacles and barriers provide the ability to prevent, discourage, or delay entry into the protected space at its outer boundaries. Some examples of physical security techniques (in escalating order) include:

• Install a fence around the site;

• Fenced sites should have a "clear zone" inside and outside the fence for unobstructed observation;

• Fenced-in sites should have the capability to have locked, secure gates;

• Installation of a security alarm system;

• Sufficient lighting in and around the site;

• Random checks of lighting and fencing in and around the site;

• Increase testing the security alarm systems;

• Increase testing the site alarm system with local law enforcement; and

• Locking hardware for gates should be case-hardened chain and high-security padlocks;

• Employ additional portable lighting in and around the site for critical assets, and

• Employ obstacles or barriers in addition to standard fencing. Examples would be using concertina or razor wire to provide a double fence, or placing Jersey barriers to restrict vehicular traffic. While the concertina wire or Jersey barriers would have to already be on site, they can be put in place very quickly.

b. Badge System - An access badge system is an effective method to control entry to the company facilities, offices, and restricted areas other places that have access controlled entry points. Entry points may be doors, turnstiles, parking gates or other controlled entry points. Access badges use various technologies to identify the holder of the badge to the access control system. The most common technologies are magnetic stripe, proximity, barcode, smart cards and various biometric devices. The access badge contains information in digital form that is decoded by a card reader. The information is transmitted to the access control system. The access control system is a computer running access control http://en.wikipedia.org/wiki/Access_control http://en.wikipedia.org/wiki/Magnetic_stripe http://en.wikipedia.org/wiki/Barcode http://en.wikipedia.org/wiki/Smart_card http://en.wikipedia.org/wiki/Biometric http://en.wikipedia.org/wiki/Computer software that makes access control decisions based on information about the holder of the access badge. If the credential has the proper privilege the access control system unlocks the controlled access point.

Simultaneously, information about the transaction is stored in the access control system for later retrieval.

Reports can be generated that will reveal who entered what portal at what time. Considerations for a badge system include:

• Establish a control and custody process for the identification badge program;

• Enforce display of badge for employees while at work and for visitors;

• Require photo identification badges for permanent employees and long term visitors;

• Limit site access to one entrance and exit for visitors;

c. Intrusion Detection - Use of alarms, lightning, and locks provide enhanced security for protected space and improve the reliability of traditional physical security tactics, such as employee training, guards, and fencing. Each improvement is designed to restrict access to authorized personnel.

Additional security measures that directly enhance the physical protection of property include:

• Training for employees to recognize unauthorized people inside the facility;

• Institute periodic roving patrols of the facility perimeter by guard force;

• Install a property alarm system;

• Integrate alarm systems with security force and regularly exercise and check for reliability;

• Tie site alarm system into local law-enforcement department;

• Have a video camera monitor areas not under direct observation;

• Employ explosive detection devices; and

• Use metal detectors/x-ray machines to screen personnel, visitors, and bags.

d. Personnel Protection – Unfortunately, the threat of violence in the workplace is a variable which you may choose to address as part of your security plan. The first step in protecting the work force from physical threats is educating the individual to recognize threatening situations. This must also be supported by systems and infrastructure that provide the capability for a proper response. Robust communications, particularly the ability to communicate as well as function under duress, are an essential consideration. The response capability should be described in terms of timing, capability, and quantity.

Any response that can disrupt or otherwise degrade a potential attack scenario, without placing additional people at risk or otherwise raising the potential target value, may be considered as a security measure.

For example:

• Determine if the organization has personnel deemed as critical and more likely to be targeted, if so, establish procedures for the protection of personnel deemed critical;

• Identify and assess potential safe havens within buildings to use in emergencies (safe havens are areas that are more survivable than other areas in buildings-basements, hallways, inner rooms, or stairwells-and that generally offer a significant barrier to an intruder);

• Inform employees about buildings that contain safe havens;

• Have an emergency evacuation plan;

• Ensure the emergency evacuation plan has escape routes, emergency lighting, and exits; and

• Establish emergency lockdown/shelter-in-place procedures, then;

o Conduct drills moving employees to designated safe havens; and o Periodically run drills to test the emergency evacuation plan;

o Establish procedures for retaining essential employees on site.

VI. Information Security – Provide a detailed description of your Information Security Program designed to protect information systems against unauthorized access to or modification of information, whether in storage, processing or transit, and against the denial of service to authorized users or the provision of service to unauthorized users, including those measures necessary to detect, document, and counter such threats. This program should address physical and electronic media.

a. Identifying physically marking and then protecting sensitive program information are the lynchpins of an effective information security program. BARDA contracts are unclassified but information within the program can be designated as proprietary, company confidential, Critical Infrastructure Program information, sensitive but unclassified, and other handling designations. By identifying sensitive information and using appropriate markings warns and informs the recipient of the degree of protection required. Examples of information security for the protection of physical media include:

• Identify information that should be considered sensitive (proposed listing at Appendix A)

• Institute security training program on the marking, handling, dissemination, and destruction of physical and electronic media containing sensitive information.

• Develop a destruction policy using approved methods (burning or shredding)

• Establish destruction or turn-in policies for computer equipment.

b. The use of systems can enhance security and allows for the rapid dissemination of information.

However, these systems must be secure or protected to prevent intrusion. Once again, some security measures are listed below. Develop one or more primary objectives and then use the measures below, or others you think of, to satisfy each primary objective. Examples of IT Systems security techniques include:

• Install a computer-intrusion-detection system;

• Monitor Internet activity in your organization;

• Periodically test back-up power for communication systems;

• Hire consultants to attempt to penetrate your system and/or assess your vulnerability to outside hackers;

• Do not disseminate sensitive program information over the unsecured internet connection;

• Develop policies limiting downloading capabilities from company computer systems; and

• Identify specific sanitized laptops for use by company personnel on travel.

VII. Security Awareness Program – Describe in detail your Security Awareness Program which educates your personnel of company security policies and the need to protect the physical and, especially, information assets of your company. An effective Security Awareness Program gains the trust of its personnel and continually re-enforces practical security responsibilities throughout the service of each employee. Examples of security awareness programs include include:

• Security education training as part of new employee indoctrination;

• Post reminders in the work place that includes Security points of contact for questions and to report violations;

• Annual security education training, highlighting the need for continued vigilance and improvements made in the company security strategies and policies;

• Host outside guest speakers to discuss the importance of security, threats, and personal protection;

• Conduct after hour inspections to ensure compliance with company policies;

• Provide incentives for recognized excellence in security awareness.

VIII. Transportation Security - Describe in detail your Transportation Security Program which protects materials while in transit from theft, destruction, manipulation, or damage.

a. A vehicle or shipment in transit represents not just a moving target, but a critical space in constant exposure to an uncontrolled environment harboring a diversity of threats. When defining primary objectives, it is important to remember that the cargo is the prime source of consequential damage.

Security measures that do not, in some way, link directly to the covered materials, but just the vehicle, may be of limited value. Examples of transportation security considerations include:

• Plan for primary (phone/cell phone), secondary (radio), and tertiary (satellite tracking) means of communications;

• Install by-pass and shutdown mechanisms;

• Install panic-button option in vehicles;

• Install theft-protection devices to disable fuel, hydraulics, and/or electrical systems;

• Seal trailers/containers;

• Driver should always have a communication device readily available

• Institute a two-person rule

• Inspect cargo manifest and match with cargo;

• See that all tractor/trailer access panels/doors are locked and seals remain intact/undamaged;

• Implement a search plan for tractors and trailers on the site;

• Routinely check truck transits to ensure routing plan is on file prior to departure

• Coordinate routes with law enforcement authorities

• Devise an Incident Management Plan

• Arrange with consignee to notify shipper and carrier if the cargo does not reach its destination, and

• Purchase all other necessary technology devices to be installed.

b. Tracking Systems - satellite systems and other technologies are excellent examples of graduated security capabilities. The frequency of location and status checks can be varied with alert levels and tailored to specific materials, reflecting the threat environment and potential consequences.

c. Cargo Status and Seals - Cargo seals, tamper-proof locks, and other technology may be utilized. Some cargo seals are designed to show signs of physical tampering, while others are electronic and can provide wireless notification if breached by an unauthorized individual. However, a basic locking system may be all that is necessary to deter theft. Of course, seals are not appropriate in all circumstances.

For example, it would be counterproductive to use seals for bulk shipments which require multiple pickups or drops (unloading). Check paperwork to ensure it is complete and accurate.

File details come from the government source that posted it. Updated .