Volume_3_-_Technical_Approach_&_Proj_Pln_&_Sch_(Amd_2).doc

DOC document 81 KB Posted

Attached to
IT Security Services Federal contract opportunity
Solicitation number
RFP-ADF-OIT-17-0001
Issued by
Department of the Treasury Bureau of the Fiscal Service

About this file

Updated Volume 3 template

View the file

Other files for this federal contract opportunity

Other files attached to IT Security Services, newest first.
File Type Posted
Amd_3_-_QA.pdf PDF
Attch_A_(1-3)_-_Pricing_Sheet_(Amd_2).xlsx XLSX spreadsheet
RFP-ADF-OIT-17-0001(Amd_2).pdf PDF
Amd_2_-_Q&A_2-3-17.pdf PDF
Amd_1_-_Q&A.pdf PDF
Volume_2_-_Experience_&_Capabilities.docx DOCX document
Attch_A_(1-3)_-_Pricing_Sheet.xlsx XLSX spreadsheet
Volume_3_-_Technical_Approach.doc DOC document
Volume_4_-_Quality_Control_Plan.doc DOC document
RFP-ADF-OIT-17-0001.pdf PDF
IPP_Waiver_Form.pdf PDF
Volume_1_-_Contractual_Documents.docx DOCX document
Attch_B_-_Nondisclosure_Agreement.pdf PDF
Volume_5_-_Past_Performance.docx DOCX document
Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFP-ADF-OIT-17-0001

Volume 3 – Technical Approach Offeror: ???????

Technical Approach: Offerors shall provide a Technical Approach that clearly and sufficiently demonstrates their understanding and ability to successfully perform the tasks and provide the corresponding deliverables within the time frame requested.

6.0 TASKS AND DELIVERABLES

The Contractor’s personnel shall work cooperatively with USADF to perform the following requirements during each period executed under the contract:

6.1. Bi-Weekly Status and Project Plan & Schedule

The Contractor shall hold at a maximum 3 1/2 hour bi-weekly meeting with the Government to discuss and provide an update on the Project Plan & Schedule. The Contractor shall prepare and maintain a Project Plan & Schedule that includes the following:

a. Project timeline, mandatory tasks and corresponding deliverables with durations

b. Project progress for task and corresponding deliverables accomplished in the reporting period and project milestones

c. Task and corresponding deliverables to be accomplished in next reporting period

d. Project risks, if any, and anticipated delays

Deliverable:

The Contractor shall provide a complete up to date Project Plan & Schedule to the COR at each bi-weekly meeting. COR will review the project plan and communicate any request(s) for changes or acceptance during the meeting. All rework must be submitted by email to the COR within two (2) business days after the request for final approval.

Throughout all tasks listed in Section 6.0 of the PWS, the Contractor shall provide a written copy of the updated Project Plan & Schedule to the COR, when applicable, within two (2) business days of the agreed upon verbal changes.

Offerors Technical Approach:

6.2 IT Security Engineering Services 6.2.1 The Contractor shall assist and advice on security architecture reviews of USADF core architectures, platforms and authentication mechanisms and compliance, to include legacy, new project, and other architectures and changes within them, and cloud activities.

6.2.2 The Contractor shall conduct and coordinate security risk assessments and penetration or other tests and provide written risk assessment reports for technologies relevant to USADF. These assessments shall be based on Industry standards, the latest final NIST 800 800-53 security controls, various SAN Institutes, FedRAMP control baselines for cloud hosted systems and Center for Security (CIS) benchmarks etc.

6.2.3 The Contractor shall conduct quarterly vulnerability scanning (once every 3 months) in accordance with USADF Continuous Monitoring Plan, and prioritize actionable recommendations and findings by risk, to include eliminating false positives as much as possible, and to include validating the exploitability of weakness, as approved by the CISO.

6.2.4 The Contractor shall conduct Security Assessments, Accreditation and Authorization processes for both the program and general support systems.

6.2.5 The Contractor shall complete and sign a rules of engagement form, coordinate with stakeholders, and have approved written and signed permission from the CISO prior to performing vulnerability scans, penetration testing and validating network security exploits.

6.2.6 The Contractor shall perform an annual configuration baseline for available operating systems at USADF based on USGCB and provide USADF IT staff on recommendations and mitigation strategies.

Deliverables:

The Contractor shall provide the following deliverables:

a. Upon review of USADF security architecture, the Contractor shall provide a recommendation and guideline on addressing authentication mechanisms and compliance.

b. Produce a security risk assessment for the following:

i. General Support System (cloud-based and internal systems)

ii. Grant Management Database System (this is a SaaS cloud-based)

c. Quarterly vulnerability scan reports and remediation strategies

d. Security Control Assessment reports, update POA&Ms, Systems Security Plans, recommend Accreditation and Authorization of Systems if applicable for the program and general support systems.

e. Submit a Rules of Engagement to USADF CISO for review and signature.

f. Submit a systems configuration baseline report from scanning results with the USADF supplied USGCB software and plugins. Submit a detailed remediation strategy for “FAILED” configuration settings from the report.

Offerors Technical Approach:

6.3 Continuous Monitoring Plan The Contractor shall assist USADF in implementing its continuous monitoring strategy and program by ensuring that continuous monitoring activities are implemented. The following are mechanisms that are to be monitored or assured implemented by the Contractor to address security impacts on the USADF information system resulting to changes to hardware, software, firmware, and operational environment, internal and external threats.

6.3.1 Event Management

6.3.2 Access Control (GSS & PSS)

6.3.3 Intrusion Prevention System

6.3.4 POA&M Remediation

6.3.5 Anti-Virus/Malware Monitoring

6.3.6 Patch Management

6.3.7 Configuration/Change Management

6.3.8 Vulnerability Scans

6.3.9 Systems and Asset Inventory

6.3.10 Ongoing Security Control Assessments and Continuous Authorization

6.3.11 Security Policy and Procedure Review and Updating

6.3.12 Incident Response and US-CERT Reporting

6.3.13 IT Security Training

6.3.14 Systems Audit and Audit Reporting

Deliverables:

The Contractor shall follow and produce the following reporting metrics to the CISO.

a. Event Management Reports (Weekly) – Events from the Syslog system SEIM shall be reviewed on a weekly basis and a network access report shall be prepared identifying users accessing the network and failed logon attempts as part of the weekly security report. The reports shall also identify errors reported from other network devices (firewalls, IPS, Switches etc.)

b. Access Control (Monthly) – All Office 365 and GISEL users shall be reviewed for inactive accounts and a security report submitted to the CISO for signature. Inactive accounts in both systems shall be deactivated after 90 days.

c. Intrusion Prevention System (Weekly) – IPS monitoring shall be conducted on a continuous basis and weekly security report produced and submitted to the CISO.

d. POA&M Controls (Quarterly) – POA&M report shall be reviewed, milestones updated on a quarterly basis and as a result of the annual assessment.

e. Anti-Virus/Malware Monitoring (Weekly) – Anti-virus and Anti-Malware monitoring of all Windows based servers, workstations and laptops shall be reviewed on a weekly basis and results included in the weekly security report.

f. Patch Management (Monthly) – Patches to the USADF systems shall be managed and recorded through the change control process for patches identified in the US-CERT weekly vulnerability summary report. Normal patches identified through the HEAT Endpoint system shall be pushed to endpoint systems on the defined schedule. A monthly patch management report shall be submitted to the CISO.

g. Configuration/Change Management (Annual) – Compliance scans for USGCB baselines shall be conducted annually. A resulting report shall be submitted to the CISO with the appropriate recommendations.

h. Vulnerability Scans (Quarterly) – Vulnerability scans shall be conducted on a quarterly basis. A resulting vulnerability scan report and a corrective action plan submitted to the CISO with a timetable on remedying identified vulnerabilities.

i. Systems and Asset Inventory (Annually) – Asset Inventory conducted annually and results included in the annual security report.

j. Ongoing Control Assessments and Continuous Authorization (Annually) - Security control assessments shall be conducted throughout the year for a subset of controls. There shall also be updates to the security assessment documentation each year to include the FIPS 199, Vulnerability Assessment Report, POA&M (also quarterly), System Security Plan, Security Assessment Report, and Accreditation Memo. The controls shall be certified each year and the AO presented with a Security Assessment Report for continued authorization at the AO’s discretion.

k. Security, Policy, Guidelines, Procedure and Plan Review (Annually) - Policies, guideline, procedures, and plans shall be reviewed and updated (if needed) in accordance with the USADF-defined frequency. A notation shall be made in the history of revisions table of each document.

NIST publications and FISMA guidance shall be reviewed on a semi-annual basis to keep current on updates, revisions and changes.

l. Incident Response and US-CERT Reporting Alerts from US-CERT and incident reports to US-CERT shall be conducted on a continuous basis. A record will be kept of notification alerts and submissions to US-CERT.

m. IT Security Training (Annually) - The USADF shall maintain current records of all system users who take security training, including basic security awareness and role-based security training for a minimum of three years.

Offerors Technical Approach:

6.4 Security Policies, Guidelines and Procedures 6.4.1 The Contractor shall assist the CIO in drafting USADF security policies, guidelines and procedures where these policies, guidelines and procedures either are missing or don’t exist.

6.4.2 The Contractor shall assist the office of the CIO in updating existing USADF policies in accordance with OMB guidelines and latest NIST Standard publications series.

6.4.3 The Contractor shall assist the office of the CIO in drafting official CIO/CISO communications, liaising with customers and external partners, writing non-security jargon based policies and standard operating procedures, and assisting the CISO in documenting and executing strategic plans.

6.4.4 The Contractor shall assist the CIO/CISO in providing the following:

a. Shall review, revise and update USADF written materials in accordance with agency requirements as directed.

b. Shall review and update USADF Security Assessment and Authorization (SA&A) package, policy methodologies and standard operating procedures. The scope of this task shall include the identification, creation, update, and retirement of procedural documentation that is either in place, in need of revision. The Contractor shall ensure materials written for USADF include policy manual sections, directives, and procedures, are in risk-based compliance with USADF, FISMA, Office of Management and Budget (OMB) and NIST requirements.

c. The Contractor shall support the development, refinement, delivery and review of post self-assessments

d. The Contractor shall participate in annual FISMA audit activities and Security Assessments and Authorization.

e. The Contractor shall provide technical writing and support, as required for implementing all strategy, communications, and documentation aspects of USADF IT Security program.

Deliverable:

The Contractor shall provide the following deliverables with regards to the tasks in 6.3

a. Monthly COR meeting participation

b. Actionable recommendations prioritized by risk

c. Update USADF IT Security Implementation Plan Handbook to reflect current NIST Standard Publications.

d. Revise and Update the following security packages for both the program and general support systems to reflect USADF current operating environment, FISMA and NIST control requirements. These reports shall be delivered to the CISO by April 15th, 2017.

i. Risk Assessment Reports

ii. Security Control Assessments

iii. Systems Security Plans

iv. Systems Assessment reports

v. Contingency Plans

vi. Privacy Controls

e. Review ISA, MOUs

f. Perform assessments and deliver C&A package with actionable recommendations on cloud-based systems if necessary including issuing an Authority-to-operate (ATO) for both systems.

Offerors Technical Approach:

File details come from the government source that posted it. Updated .