Volume_3_-_Technical_Approach_&_Proj_Pln_&_Sch_(Amd_2).doc
DOC document 81 KB Posted
- Attached to
- IT Security Services Federal contract opportunity
- Solicitation number
- RFP-ADF-OIT-17-0001
About this file
Updated Volume 3 template
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amd_3_-_QA.pdf | ||
| Attch_A_(1-3)_-_Pricing_Sheet_(Amd_2).xlsx | XLSX spreadsheet | |
| RFP-ADF-OIT-17-0001(Amd_2).pdf | ||
| Amd_2_-_Q&A_2-3-17.pdf | ||
| Amd_1_-_Q&A.pdf | ||
| Volume_2_-_Experience_&_Capabilities.docx | DOCX document | |
| Attch_A_(1-3)_-_Pricing_Sheet.xlsx | XLSX spreadsheet | |
| Volume_3_-_Technical_Approach.doc | DOC document | |
| Volume_4_-_Quality_Control_Plan.doc | DOC document | |
| RFP-ADF-OIT-17-0001.pdf | ||
| IPP_Waiver_Form.pdf | ||
| Volume_1_-_Contractual_Documents.docx | DOCX document | |
| Attch_B_-_Nondisclosure_Agreement.pdf | ||
| Volume_5_-_Past_Performance.docx | DOCX document |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFP-ADF-OIT-17-0001
Volume 3 – Technical Approach Offeror: ???????
Technical Approach: Offerors shall provide a Technical Approach that clearly and sufficiently demonstrates their understanding and ability to successfully perform the tasks and provide the corresponding deliverables within the time frame requested.
6.0 TASKS AND DELIVERABLES
The Contractor’s personnel shall work cooperatively with USADF to perform the following requirements during each period executed under the contract:
6.1. Bi-Weekly Status and Project Plan & Schedule
The Contractor shall hold at a maximum 3 1/2 hour bi-weekly meeting with the Government to discuss and provide an update on the Project Plan & Schedule. The Contractor shall prepare and maintain a Project Plan & Schedule that includes the following:
a. Project timeline, mandatory tasks and corresponding deliverables with durations
b. Project progress for task and corresponding deliverables accomplished in the reporting period and project milestones
c. Task and corresponding deliverables to be accomplished in next reporting period
d. Project risks, if any, and anticipated delays
Deliverable:
The Contractor shall provide a complete up to date Project Plan & Schedule to the COR at each bi-weekly meeting. COR will review the project plan and communicate any request(s) for changes or acceptance during the meeting. All rework must be submitted by email to the COR within two (2) business days after the request for final approval.
Throughout all tasks listed in Section 6.0 of the PWS, the Contractor shall provide a written copy of the updated Project Plan & Schedule to the COR, when applicable, within two (2) business days of the agreed upon verbal changes.
Offerors Technical Approach:
6.2 IT Security Engineering Services 6.2.1 The Contractor shall assist and advice on security architecture reviews of USADF core architectures, platforms and authentication mechanisms and compliance, to include legacy, new project, and other architectures and changes within them, and cloud activities.
6.2.2 The Contractor shall conduct and coordinate security risk assessments and penetration or other tests and provide written risk assessment reports for technologies relevant to USADF. These assessments shall be based on Industry standards, the latest final NIST 800 800-53 security controls, various SAN Institutes, FedRAMP control baselines for cloud hosted systems and Center for Security (CIS) benchmarks etc.
6.2.3 The Contractor shall conduct quarterly vulnerability scanning (once every 3 months) in accordance with USADF Continuous Monitoring Plan, and prioritize actionable recommendations and findings by risk, to include eliminating false positives as much as possible, and to include validating the exploitability of weakness, as approved by the CISO.
6.2.4 The Contractor shall conduct Security Assessments, Accreditation and Authorization processes for both the program and general support systems.
6.2.5 The Contractor shall complete and sign a rules of engagement form, coordinate with stakeholders, and have approved written and signed permission from the CISO prior to performing vulnerability scans, penetration testing and validating network security exploits.
6.2.6 The Contractor shall perform an annual configuration baseline for available operating systems at USADF based on USGCB and provide USADF IT staff on recommendations and mitigation strategies.
Deliverables:
The Contractor shall provide the following deliverables:
a. Upon review of USADF security architecture, the Contractor shall provide a recommendation and guideline on addressing authentication mechanisms and compliance.
b. Produce a security risk assessment for the following:
i. General Support System (cloud-based and internal systems)
ii. Grant Management Database System (this is a SaaS cloud-based)
c. Quarterly vulnerability scan reports and remediation strategies
d. Security Control Assessment reports, update POA&Ms, Systems Security Plans, recommend Accreditation and Authorization of Systems if applicable for the program and general support systems.
e. Submit a Rules of Engagement to USADF CISO for review and signature.
f. Submit a systems configuration baseline report from scanning results with the USADF supplied USGCB software and plugins. Submit a detailed remediation strategy for “FAILED” configuration settings from the report.
Offerors Technical Approach:
6.3 Continuous Monitoring Plan The Contractor shall assist USADF in implementing its continuous monitoring strategy and program by ensuring that continuous monitoring activities are implemented. The following are mechanisms that are to be monitored or assured implemented by the Contractor to address security impacts on the USADF information system resulting to changes to hardware, software, firmware, and operational environment, internal and external threats.
6.3.1 Event Management
6.3.2 Access Control (GSS & PSS)
6.3.3 Intrusion Prevention System
6.3.4 POA&M Remediation
6.3.5 Anti-Virus/Malware Monitoring
6.3.6 Patch Management
6.3.7 Configuration/Change Management
6.3.8 Vulnerability Scans
6.3.9 Systems and Asset Inventory
6.3.10 Ongoing Security Control Assessments and Continuous Authorization
6.3.11 Security Policy and Procedure Review and Updating
6.3.12 Incident Response and US-CERT Reporting
6.3.13 IT Security Training
6.3.14 Systems Audit and Audit Reporting
Deliverables:
The Contractor shall follow and produce the following reporting metrics to the CISO.
a. Event Management Reports (Weekly) – Events from the Syslog system SEIM shall be reviewed on a weekly basis and a network access report shall be prepared identifying users accessing the network and failed logon attempts as part of the weekly security report. The reports shall also identify errors reported from other network devices (firewalls, IPS, Switches etc.)
b. Access Control (Monthly) – All Office 365 and GISEL users shall be reviewed for inactive accounts and a security report submitted to the CISO for signature. Inactive accounts in both systems shall be deactivated after 90 days.
c. Intrusion Prevention System (Weekly) – IPS monitoring shall be conducted on a continuous basis and weekly security report produced and submitted to the CISO.
d. POA&M Controls (Quarterly) – POA&M report shall be reviewed, milestones updated on a quarterly basis and as a result of the annual assessment.
e. Anti-Virus/Malware Monitoring (Weekly) – Anti-virus and Anti-Malware monitoring of all Windows based servers, workstations and laptops shall be reviewed on a weekly basis and results included in the weekly security report.
f. Patch Management (Monthly) – Patches to the USADF systems shall be managed and recorded through the change control process for patches identified in the US-CERT weekly vulnerability summary report. Normal patches identified through the HEAT Endpoint system shall be pushed to endpoint systems on the defined schedule. A monthly patch management report shall be submitted to the CISO.
g. Configuration/Change Management (Annual) – Compliance scans for USGCB baselines shall be conducted annually. A resulting report shall be submitted to the CISO with the appropriate recommendations.
h. Vulnerability Scans (Quarterly) – Vulnerability scans shall be conducted on a quarterly basis. A resulting vulnerability scan report and a corrective action plan submitted to the CISO with a timetable on remedying identified vulnerabilities.
i. Systems and Asset Inventory (Annually) – Asset Inventory conducted annually and results included in the annual security report.
j. Ongoing Control Assessments and Continuous Authorization (Annually) - Security control assessments shall be conducted throughout the year for a subset of controls. There shall also be updates to the security assessment documentation each year to include the FIPS 199, Vulnerability Assessment Report, POA&M (also quarterly), System Security Plan, Security Assessment Report, and Accreditation Memo. The controls shall be certified each year and the AO presented with a Security Assessment Report for continued authorization at the AO’s discretion.
k. Security, Policy, Guidelines, Procedure and Plan Review (Annually) - Policies, guideline, procedures, and plans shall be reviewed and updated (if needed) in accordance with the USADF-defined frequency. A notation shall be made in the history of revisions table of each document.
NIST publications and FISMA guidance shall be reviewed on a semi-annual basis to keep current on updates, revisions and changes.
l. Incident Response and US-CERT Reporting Alerts from US-CERT and incident reports to US-CERT shall be conducted on a continuous basis. A record will be kept of notification alerts and submissions to US-CERT.
m. IT Security Training (Annually) - The USADF shall maintain current records of all system users who take security training, including basic security awareness and role-based security training for a minimum of three years.
Offerors Technical Approach:
6.4 Security Policies, Guidelines and Procedures 6.4.1 The Contractor shall assist the CIO in drafting USADF security policies, guidelines and procedures where these policies, guidelines and procedures either are missing or don’t exist.
6.4.2 The Contractor shall assist the office of the CIO in updating existing USADF policies in accordance with OMB guidelines and latest NIST Standard publications series.
6.4.3 The Contractor shall assist the office of the CIO in drafting official CIO/CISO communications, liaising with customers and external partners, writing non-security jargon based policies and standard operating procedures, and assisting the CISO in documenting and executing strategic plans.
6.4.4 The Contractor shall assist the CIO/CISO in providing the following:
a. Shall review, revise and update USADF written materials in accordance with agency requirements as directed.
b. Shall review and update USADF Security Assessment and Authorization (SA&A) package, policy methodologies and standard operating procedures. The scope of this task shall include the identification, creation, update, and retirement of procedural documentation that is either in place, in need of revision. The Contractor shall ensure materials written for USADF include policy manual sections, directives, and procedures, are in risk-based compliance with USADF, FISMA, Office of Management and Budget (OMB) and NIST requirements.
c. The Contractor shall support the development, refinement, delivery and review of post self-assessments
d. The Contractor shall participate in annual FISMA audit activities and Security Assessments and Authorization.
e. The Contractor shall provide technical writing and support, as required for implementing all strategy, communications, and documentation aspects of USADF IT Security program.
Deliverable:
The Contractor shall provide the following deliverables with regards to the tasks in 6.3
a. Monthly COR meeting participation
b. Actionable recommendations prioritized by risk
c. Update USADF IT Security Implementation Plan Handbook to reflect current NIST Standard Publications.
d. Revise and Update the following security packages for both the program and general support systems to reflect USADF current operating environment, FISMA and NIST control requirements. These reports shall be delivered to the CISO by April 15th, 2017.
i. Risk Assessment Reports
ii. Security Control Assessments
iii. Systems Security Plans
iv. Systems Assessment reports
v. Contingency Plans
vi. Privacy Controls
e. Review ISA, MOUs
f. Perform assessments and deliver C&A package with actionable recommendations on cloud-based systems if necessary including issuing an Authority-to-operate (ATO) for both systems.
Offerors Technical Approach:
File details come from the government source that posted it. Updated .