Statement of Work.pdf

PDF 71 KB Posted

Attached to
AFMC Training Federal contract opportunity
Solicitation number
FA930224Q0073
Issued by
Department of the Air Force Materiel Command Test Center

About this file

This document is a Statement of Work (SOW) for two training courses to be provided to the Air Force Test Center (AFTC) at Edwards Air Force Base (AFB). The first course is an Information System Security Officer (ISSO) course for up to 15 students that will cover topics such as implementing and assessing security controls, system auditing, incident handling, and compliance reviews. The second course is a Joint SAP Implementation Guide (JSIG) based Risk Management Framework training course for up to 22 students that will provide information on risk assessment and security authorization for DoD and SAP information systems.

The related federal contract opportunity is a Request for Quote (RFQ) issued by the Department of the Air Force Materiel Command Test Center, a defense agency, with Solicitation Number FA930224Q0073. The RFQ is a total small business set-aside with a NAICS code of 611430 and a size standard of $15,000,000. Offers are due by August 29, 2024 at 10:00 AM Pacific Time. The Government will award a firm fixed-price contract based on best value. The period of performance is October 1 to November 29, 2024, with the training to be conducted at Edwards AFB.

View the file

Other files for this federal contract opportunity

Other files attached to AFMC Training, newest first.
File Type Posted
AFMC Training-Combo Synopsis Solicitation.pdf PDF
Solicitation - FA930224Q0073.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RMF/ISSO Training Statement of Work

1. Support USAF/AFMC by providing an Information System Security Officer (ISSO) course for up to fifteen students at a USAF/AFMC training facility located within Edwards AFB. This course will provide students with various methods and approaches to implement, assess, and monitor technical Controls within the DoD and SAP Communities. This course will deliver policy guidelines, methodologies, plans, processes, templates, tools and system hardening requirements; as well as explain the roles, responsibilities, and technical security control implementation and assessment requirements associated within the RMF environments. This course will also allow students to become familiar with various DoD provided templates, processes, and tools through hands-on computer labs and exercises.

This course will take the student through the daily life on an ISSO and the process of ‘actually’ completing documentation, running scans (SCC, ACAS, others) on systems, implementing, assessing, monitoring technical controls, incident response (data spill/Malcode clean-up, forensics), data transfer process, system auditing, and continuous monitoring.

Various topics will be introduced, to include:

• Roles and Responsibilities of the ISSO

• Implementing and Assessing Security Controls (Secure Configuration)

• System Auditing

• Information System Continuous Monitoring

• Documentation Creation (SSP, RAR, SAR, POA&M, ISCM Plan, Assessment

Plan)

• Incident Handling and Response

• Assured File Transfers

• Compliance Reviews and Self-Inspections

2. Support USAF/AFMC by providing a Joint SAP Implementation Guide (JSIG) based

Risk Management Framework training course for up to 22 students via a platform (in-person) training environment.

This course is designed to provide Program Security, Information System Security, and Cybersecurity Professionals responsible for implementing and assessing security polices; practices, procedures and technologies with information and training for the implementation and conduct of Department of Defense (DoD), Special Access Program (SAP) and Intelligence Community (IC) information systems risk assessment and security authorization in accordance with the Risk Management Framework, DoD, SAP guidance and Intelligence Community Directive 503.

This course will provide students with new methods and approaches to assessing and authorizing IT systems within DoD and SAP community and partner organizations in the Intelligence Community. This course will deliver new policy guidelines, methodologies, plans, processes, and templates; as well as explain the roles and responsibilities associated with the new Risk Management Framework and the systems development life cycle. This course will also allow students to become familiar with the RMF process and Joint Special Access Program Implementation Guide (JSIG) templates and processes through case studies and exercises.

File details come from the government source that posted it. Updated .