C003 Continuity of Operations Plan.pdf
PDF 483 KB Posted
- Attached to
- Special Notice-Amendment 0009 Federal contract opportunity
- Solicitation number
- W15QKN-17-R-1042
About this file
This document package includes a federal contract opportunity solicitation and the associated contract data requirements list.
The solicitation is for Reserve Health Readiness Program III services, including immunizations, physical examinations, mental health assessments, dental services, and laboratory services to support reserve components throughout the U.S. and at designated sites. The Army Contracting Command - New Jersey will issue the solicitation on September 30, 2017 through full and open competition as a single-award, five-year indefinite delivery indefinite quantity contract with both firm-fixed-price and cost reimbursement task orders. The anticipated North American Industry Classification System and size standard are 621112 for general health care services at $11 million. Interested parties should monitor the Federal Business Opportunities website.
The associated contract data requirements list outlines reporting requirements for the continuity of operations plan, including submission through the contracting officer, distribution statements, and frequencies. It provides submission details for the draft, final, regulation, and reproduction documents.
Not Listed
View the file
Other files for this federal contract opportunity
Show all 50
Special Notice-Amendment 0009 has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DD FORM 1423-1, FEB 2001
CONTRACT DATA REQUIREMENTS LIST
(1 Data Item)
PREVIOUS EDITION MAY BE USED.
Form Approved OMB No. 0704-0188
The public reporting burden for this collection of information is estimated to average 110 hours per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Executive Services and Communications Directorate (0704-0188). Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number. Please do not return your form to the above organization. Send completed form to the Government Issuing Contracting Officer for the Contract/PR No. listed in Block E.
A. CONTRACT LINE ITEM NO. B. EXHIBIT C. CATEGORY:
TDP ________ TM _______ OTHER
D. SYSTEM/ITEM E. CONTRACT/PR NO. F. CONTRACTOR
1. DATA ITEM NO. 2. TITLE OF DATA ITEM 3. SUBTITLE
4. AUTHORITY (Data Acquisition Document No.) 5. CONTRACT REFERENCE 6. REQUIRING OFFICE
7. DD 250 REQ
8. APP CODE
9. DIST STATEMENT
REQUIRED
10. FREQUENCY
11. AS OF DATE
12. DATE OF FIRST SUBMISSION
13. DATE OF SUBSEQUENT
SUBMISSION
14. DISTRIBUTION
a. ADDRESSEE
b. COPIES
Draft Final
Reg Repro
15. TOTAL
16. REMARKS
17. PRICE GROUP
18. ESTIMATED
TOTAL PRICE
G. PREPARED BY H. DATE I. APPROVED BY J. DATE
Page of Pages
A. CONTRACT LINE ITEM NO.
DD FORM 1423‐1, FEB 2001 Page ___ of ___ Pages
16. REMARKS (Continued)
CONTRACT DATA REQUIREMENTS LIST
(1 Data Item)
F. CONTRACTORE. CONTRACT/PR NO.
C. CATEGORY:
TDP _____ TM _____ OTHER ________________________________
D. SYSTEM/ITEM
B. EXHIBIT
DHA
November 2014 Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as intended, and support the security policies of the Defense Health Agency.”
Checklist and Certification for Minimum Level of Enhanced Safeguarding for Unclassified DoD Information
Contract [Insert TRICARE Contract #] Processed in accordance with provisions of [insert reference #] and CDRL [insert CDRL #]
CERTIFICATION OF COMPLIANCE: I certify that I am an official representative for [insert name of contractor], that I have authority to sign this document and obligate [insert name of contractor] to the statements made in this document, and that I have personal knowledge of the matters to which this certification applies. I also certify that [insert name of contractor] is in compliance with the enhanced safeguarding requirements identified within the contract clause stated above, this document and any applicable written determinations.
Signature: Date:
Name:
Title:
Company:
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Checklist and Certification for Minimum Level of Enhanced Safeguarding for Unclassified DoD Information
Contract [Insert TRICARE Contract #] Processed in accordance with provisions of [insert reference #] and CDRL [insert CDRL #]
Special Publication 800-171 Checklist
Ref # NIST SP 800-53
MODERATE BASELINE SECURITY CONTROLS
Compliance Statement Select Assessment Method(s) Used Compliance
Date AC-1 Access Control Policy and Procedures Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-2 Account Management Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-3 Access Enforcement Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-4 Information Flow Enforcement Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-5 Separation of Duties Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-6 Least Privilege Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-6(1) LEAST PRIVILEGE
AUTHORIZED ACCESS TO SECURITY FUNCTIONS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-6(2) LEAST PRIVILEGE
NON-PRIVILEGED ACCESS FOR NONSECURITY
FUNCTIONS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date
AC-6(5) LEAST PRIVILEGE
PRIVILEGED ACCOUNTS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-6(9) LEAST PRIVILEGE
AUDITING USE OF PRIVILEGED FUNCTIONS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-6(10) LEAST PRIVILEGE
PROHIBIT NON-PRIVILEGED USERS FROM
EXECUTING PRIVILEGED FUNCTIONS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-7 Unsuccessful Logon Attempts Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-8 System Use Notification Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-11 Session Lock Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-11(1) SESSION LOCK
PATTERN-HIDING DISPLAYS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-12 Session Termination Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-17 Remote Access Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-17(1) REMOTE ACCESS
AUTOMATED MONITORING/CONTROL
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-17(2) REMOTE ACCESS
PROTECTION OF CONFIDENTIALITY/ INTEGRITY
USING ENCRYPTION
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-17(3) REMOTE ACCESS
MANAGED ACCESS CONTROL POINTS Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date
AC-17(4) REMOTE ACCESS
PRIVILEGED COMMANDS/ACCESS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-18 Wireless Access Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-18(1) WIRELESS ACCESS
AUTHENTICATION AND ENCRYPTION
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-19 Access Control for Mobile Devices Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-19(5) ACCESS CONTROL FOR MOBILE DEVICES
FULL DEVICE/CONTAINER-BASED ENCRYPTION
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-20 Use of External Information Systems Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-20(1) USE OF EXTERNAL INFORMATION SYSTEMS
LIMITS ON AUTHORIZED USE
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-20(2) USE OF EXTERNAL INFORMATION SYSTEMS
PORTABLE STORAGE DEVICES
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AC-22 Publicly Accessible Content Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date AT-1 Security Awareness and Training Policy
And Procedures Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AT-2 Security Awareness Training Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date
AT-2(2) SECURITY AWARENESS
INSIDER THREAT
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AT-3 Role Based Security Training Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AT-4 Security Training Records Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date AU-1 Audit and Accountability Policy and Procedures Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-2 Audit Events Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-2(3) AUDIT EVENTS
REVIEWS AND UPDATES
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-3 Content of Audit Records Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-3(1) CONTENT OF AUDIT RECORDS
ADDITIONAL AUDIT INFORMATION
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-5 Response to Audit Processing Failures Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-6 Audit, Review, Analysis and Reporting Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-6(3) AUDIT, REVIEW, ANALYSIS AND REPORTING
CORRELATE AUDIT REPOSITORIES
Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date AU-7 Audit Reduction & Report Generation Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-8 Time Stamps Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-8(1) TIME STAMPS
SYNCHRONIZATION WITH AUTHORITATIVE TIME
SOURCE
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-9 Protection of Audit Information Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-9(4) PROTECTION OF AUDIT INFORMATION
ACCESS BY SUBSET OF PRIVILEGED USERS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
AU-12 Audit Generation Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date CA-1 Security Assessment and Authorization Policies and Procedures Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CA-2 Security Assessments Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CA-2(1) SECURITY ASSESSMENTS
INDEPENDENT ASSESSORS Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CA-3 System Interconnections Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date
CA-3(5) SYSTEM INTERCONNECTIONS
RESTRICTIONS ON EXTERNAL SYSTEM
CONNECTIONS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CA-5 Plan of Action and Milestones Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CA-7 Continuous Monitoring Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CA-7(1) CONTINUOUS MONITORING
INDEPENDENT ASSESSMENT
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CA-9 Internal System Connections Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date CM-1 Configuration Management Policy and
Procedures Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-2 Baseline Configuration Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-2(1) BASELINE CONFIGURATION
REVIEWS AND UPDATES
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-2(7) BASELINE CONFIGURATION
CONFIGURE SYSTEMS,COMPONENTS, OR
DEVICES FOR HIGH-RISK AREAS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-3 Configuration Change Control Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date
CM-3(2) CONFIGURATION CHANGE CONTROL
TEST/VALIDATE/’DOCUMENT CHANGES
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-4 Security Impact Analysis Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-5 Access Restrictions for Change Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-6 Configuration Settings Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-7 Least Functionality Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-7(1) LEAST FUNCTIONALITY
PERIODIC REVIEW
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-7(2) LEAST FUNCTIONALITY
PREVENT PROGRAM EXECUTION
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-7(4)(5) LEAST FUNCTIONALITY
UNAUTHORIZED OR AUTHORIZED
SOFTWARE/BLACKLISTING OR WHITELISTING
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-8 Information System Component Inventory Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-8(1) INFORMATION SYSTEM COMPONENT
INVENTORY
UPDATES DURING INSTALLATIONS/REMOVALS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-8(5) INFORMATION SYSTEM COMPONENT
INVENTORY
NO DUPLICATE ACCOUNTING OF COMPONENTS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
CM-9 Configuration Management Plan Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date CM-11 User-Installed Software Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date CP-9 Information System Backup Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date IA-1 Identification & Authentication Policy and
Procedures Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IA-2 Identification & Authentication
(Organization Users) Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IA-2(1) IDENTIFICATION & AUTHENTICATION
(ORGANIZATION USERS)
NETWORK ACCESS TO PRIVILEGED ACCOUNTS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IA-2(2) IDENTIFICATION & AUTHENTICATION
(ORGANIZATION USERS)
NETWORK ACCESS TO NON-PRIVILEGED
ACCOUNTS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IA-2(3) IDENTIFICATION & AUTHENTICATION
(ORGANIZATION USERS)
LOCAL ACCESS TO PRIVILEGED ACCOUNTS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IA-2(8) IDENTIFICATION & AUTHENTICATION
(ORGANIZATION USERS)
NETWORK ACCESS TO PRIVILEGED
ACCOUNTS-REPLAY RESISTANT
Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date
IA-2(9) IDENTIFICATION & AUTHENTICATION
(ORGANIZATION USERS)
NETWORK ACCESS TO NON-PRIVILEGED
ACCOUNTS-REPLAY RESISTANT
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IA-4 Identifier Management Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IA-5 Authenticator Management Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IA-5(1) AUTHENTICATOR MANAGEMENT
PASSWORD-BASED AUTHENTICATION
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IA-6 Authenticator Feedback Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date IR-1 Incident Response Policy and Procedures Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IR-2 Incident Response Training Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IR-3 Incident Response Testing Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IR-3(2) INCIDENT RESPONSE TESTING
COORDINATION WITH RELATED PLANS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IR-4 Incident Handling Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date IR-5 Incident Monitoring Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IR-6 Incident Reporting Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IR-7 Incident Response Assistance Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
IR-8 Incident Response Plan Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date MA-1 System Maintenance Policy and Procedures Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MA-2 Controlled Maintenance Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MA-3 Maintenance Tools Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MA-3(1) MAINTENANCE TOOLS
INSPECT TOOLS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MA-3(2) MAINTENANCE TOOLS
INSPECT MEDIA
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MA-4 Nonlocal Maintenance Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MA-4(2) NONLOCAL MAINTENANCE
DOCUMENT NONLOCAL MAINTENANCE
Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date MA-5 Maintenance Personnel Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date MP-1 Media Protection Policy and Procedures Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MP-2 Media Access Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MP-3 Media Marketing Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MP-4 Media Storage Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MP-5 Media Transport Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MP-5(4) MEDIA TRANSPORT
CRYPTOGRAPHIC PROTECTION
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MP-6 Media Sanitization Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MP-7 Media Use Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
MP-7(1) MEDIA USE
PROHIBIT USE WITHOUT OWNER
Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date PE-1 Physical and Environmental Protection
Policy and Procedures Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PE-2 Physical Access Authorizations Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PE-3 Physical Access Control Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PE-4 Access Control for Transmission Medium Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PE-5 Access Control for Output Devices Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PE-6 Monitoring Physical Access Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PE-6(1) MONITORING PHYSICAL ACCESS
INTRUSION ALARMS/SURVEILLANCE
EQUIPMENT
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PE-8 Visitor Access Records Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PE-16 Delivery and Removal Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PE-17 Alternate Work Site Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date PL-1 Security Planning Policy and
Procedures Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PL-2 System Security Plan Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PL-2(3) SYSTEM SECURITY PLAN
PLAN/COORDINATE WITH OTHER
ORGANIZATIONAL ENTITIES
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PL-4 Rules of Behavior Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PL-4(1) RULES OF BEHAVIOR
SOCIAL MEDIA AND NETWORKING RESTRICTIONS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PL-8 Information Security Architecture Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date PS-1 Personnel Security Policy and
Procedures Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PS-3 Personnel Screening Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PS-4 Personnel Termination Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PS-5 Personnel Transfer Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PS-6 Access Agreements Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date PS-7 Third-Party Personnel Security Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
PS-8 Personnel Sanctions Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date SA-1 System and Services Acquisition Policy and Procedures Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
Ref # NIST SP 800-53
MODERATE BASELINE SECURITY CONTROLS
Compliance Statement Select Assessment Method(s) Used Compliance
Date RA-1 Risk Assessment Policy and Procedures Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
RA-3 Risk Assessment Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
RA-5 Vulnerability Scanning Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
RA-5(1) VULNERABILITY SCANNING
UPDATE TOOL CAPABILITY
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
RA-5(2) VULNERABILITY SCANNING
UPDATE BY FREQUENCY/PRIOR TO NEW
SCAN/WHEN IDENTIFIED
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
RA-5(5) VULNERABILITY SCANNING
PRIVILEGED ACCESS
Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date SA-2 Allocation of Resources Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SA-3 System Development Life Cycle Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SA-4 Acquisition Process Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SA-4(1) ACQUISITION PROCESS
FUNCTIONAL PROPERTIES OF SECURITY
CONTROLS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SA-4(2) ACQUISITION PROCESS
DESIGN/IMPLEMENTATION INFORMATION FOR
SECURITY CONTROLS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SA-4(9) ACQUISITION PROCESS
FUNCTIONS/PORTS/ PROTOCOLS/SERVICES IN
USE
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SA-4(10) ACQUISITION PROCESS
USE OF APPROVED PIV PRODUCTS Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SA-5 Information System Documentation Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SA-8 Security Engineering Principles Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SA-9 External Information System Services Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SA-9(2) EXTERNAL INFORMATION SYSTEMS
IDENTIFICATION OF FUNCTIONS/PORTS/
PROTOCOLS/SERVICES
Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date SA-10 Developer Configuration Management Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SA-11 Developer Security Testing and Evaluation Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date SC-1 System and Communications Protection Policy and Procedures Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-2 Application Partitioning Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-4 Information in Shared Resources Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-7 Boundary Protection Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-7(3) BOUNDARY PROTECTION
ACCESS POINTS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-7(4) BOUNDARY PROTECTION
EXTERNAL TELECOMMUNICATIONS SERVICES
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-7(5) BOUNDARY PROTECTION
DENY BY DEFAULT/ALLOW BY EXCEPTION
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-7(7) BOUNDARY PROTECTION
PREVENT SPLIT TUNNELING FOR REMOTE
DEVICES
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-8 Transmission Confidentiality and Integrity Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date
SC-8(1) TRANSMISSION CONFIDENTIALITY
AND INTEGRITY
CRYPTOGRAPHIC OR ALTERNATE PHYSICAL
PROTECTION
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-10 Network Disconnect Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-12 Cryptographic Key Establishment and Management Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-13 Cryptographic Protection Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-15 Collaborative Computing Devices Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-18 Mobile Code Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-19 Voice Over Internet Protocol Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-20 Secure Name
Address Resolution Service (Authoritative Source) Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-21 Secure Name
Address Resolution Service (Recursive or Caching Resolver)
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-22 Architecture and Provisioning for Name/
Address Resolution Service Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-23 Session Authenticity Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SC-28 Protection of Information at Rest Select
Note: “Contractors may insert one or multiple potential options in the Assessment Methods column. The organization employs Audit Review, Analysis, and Reporting through proper Integration / Scanning and Monitoring Capabilities that identify the breadth and depth of coverage. The correlation of information through vulnerability scanning determines the veracity through continuous monitoring for vulnerabilities and correlating attack detection events. The resulting methods will provide the government contractor documentation of the "depth and rigor" used in assessing the required Information Assurance Controls. The contractor must ensure that the security controls required by the contract are implemented correctly, operating as
Compliance Statement Select Assessment Method(s) Used Compliance
Date SC-39 Process Isolation Select
Compliance Statement Select Assessment Method(s) Used Compliance
Date SI-1 System and Information Integrity Policy and Procedures Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SI-2 Flaw Remediation Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SI-3 Malicious Code Protection Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SI-4 Information System Monitoring Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SI-4(4) INFORMATION SYSTEM MONITORING
INBOUND AND OUTBOUND
COMMUNICATIONS TRAFFIC
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SI-4(5) INFORMATION SYSTEM MONITORING
SYSTEM GENERATED ALERTS
Select Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SI-5 Security Alerts, Advisories, and Directives Select
Answer Interview ☐ Examine ☐ Test ☐ Click here to enter a date.
SI-16 Memory Protection Select
Written Determination <Insert Reference #> in Support of
DoDI 8582.01 Checklist for Minimum Security Controls
<Insert Date>
Contract Reference # Contractor Name Street Address City, ST ZIP
Information Assurance (IA) Control #: <Enter the specific IA Control # from the “Checklist”> IA Control Nomenclature: <Enter the specific IA Control’s Nomenclature> Compliance Statement: <Restate the Contractor’s compliance with the IA Control.> Issue:
<Provide basic “business” description for why the contractor cannot / will not meet the requirements of the NIST 800-53/A IA control as listed on Checklist and Certification for Minimum Level of Enhanced Safeguarding for Unclassified DoD Information for Minimum Security Controls.> Contractor-identified Solution:
<Provide a business-level description of the contractor’s alternative plan to satisfy the security requirements associated with the Checklist’s specific IA control.> Mitigation / Remediation Plan:
<As appropriate, provide a business-level description of the contractor’s plan of action and milestone for implementing the solution listed above.> Risk Acceptance Statement <Provide a statement the contractor accepts the risk of either implementing a technical solution different from the NIST guidance or contract operations until the NIST control can be implemented.>
| A_CONTRACT_LINE_ITEM_NO: TBD |
| B_EXHIBIT: |
| TDP: |
| OTHER: |
| DSYSTEMITEM: RHRP-3 Service Contract |
| E_CONTRACTPR_NO: W15QKN-17-R-1042 |
| FCONTRACTOR: |
| 1_DATA_ITEM_NO: C003 |
| 2_TITLE_OF_DATA_ITEM: Continuity of Operations Plan |
| 3_SUBTITLE: Continuity of Operations Plan |
| 4_AUTHORITY_Data_Acquisit: DI-MISC-81317 |
| 5_CONTRACT_REFERENCE: PWS 5.11 |
| 6_REQUIRING_OFFICE: PAT&IS |
| 7_DID_250_REQ: dd |
| 8_APP_CODE: |
| DIST_STATEMENT: B |
| 10_FREQUENCY: See Block 16 |
| 11_AS_OF_DATE: See Block 16 |
| 12_DATE_OF_FIRST_SUBMISSI: See Block 16 |
| 13_DATE_OF_SUBSEQUENT_SUB: See Block 16 |
| addressee1: Submit through the |
| draft1: |
| reg1: |
| repro1: |
| addressee2: DHA E-commerce |
| draft2: |
| reg2: |
| repro2: |
| addressee3: Extranet |
| draft3: |
| reg3: |
| repro3: |
| addressee4: (Per TOM Ch 14 Sec 1) |
| draft4: |
| reg4: |
| repro4: |
| addressee5: |
| draft5: |
| reg5: |
| repro5: |
| addressee6: |
| draft6: |
| reg6: |
| repro6: |
| addressee7: |
| draft7: |
| reg7: |
| repro7: |
| addressee8: |
| draft8: |
| reg8: |
| repro8: |
| addressee9: |
| draft9: |
| reg9: |
| repro9: |
| addressee10: |
| draft10: |
| reg10: |
| repro10: |
| addressee11: |
| draft11: |
| reg11: |
| repro11: |
| addressee12: |
| draft12: |
| reg12: |
| repro12: |
| addressee13: |
| draft13: |
| reg13: |
| repro13: |
| addressee14: |
| draft14: |
| reg14: |
| repro14: |
| addressee15: |
| draft15: |
| reg15: |
| repro15: |
| addressee16: |
| draft16: |
| reg16: |
| repro16: |
| addressee17: |
| draft17: |
| reg17: |
| repro17: |
| addressee18: |
| draft18: |
| reg18: |
| repro18: |
| addressee19: |
| draft19: |
| reg19: |
| repro19: |
| addressee20: |
| draft20: |
| reg20: |
| repro20: |
| addressee21: |
| draft21: |
| reg21: |
| repro21: |
| addressee22: |
| draft22: |
| reg22: |
| repro22: |
| addressee23: |
| draft23: |
| reg23: |
| repro23: |
| addressee24: |
| draft24: |
| reg24: |
| repro24: |
| addressee25: |
| draft25: |
| reg25: |
| repro25: |
| addressee26: |
| draft26: |
| reg26: |
| repro26: |
| addressee27: |
| draft27: |
| reg27: |
| repro27: |
| addressee28: |
| draft28: |
| reg28: |
| repro28: |
| addressee29: |
| draft29: |
| reg29: |
| repro29: |
| addressee30: |
| draft30: |
| reg30: |
| repro30: |
| addressee31: |
| draft31: |
| reg31: |
| repro31: |
| addressee32: |
| draft32: |
| reg32: |
| repro32: |
| addressee33: |
| draft33: |
| reg33: |
| repro33: |
| addressee34: |
| draft34: |
| reg34: |
| repro34: |
| addressee35: |
| draft35: |
| reg35: |
| repro35: |
| addressee36: |
| draft36: |
| reg36: |
| repro36: |
| addressee37: |
| draft37: |
| reg37: |
| repro37: |
| addressee38: |
| draft38: |
| reg38x: |
| repro38: |
| total_draft: 0 |
| total_repro: 0 |
| 16_REMARKS: FIRST SUBMISSION: |
Frequency: As Required Reporting Period Start Date: Contract Award Due Date: As determined by contract award requirement.
| 17_PRICE_GROUP: |
| ESTIMATED_TOTAL_PRICE: |
| G_PREPARED_BY: Kenneth C. Jacobs |
| H_DATE: 01/07/2015 |
| 1_APPROVED_BY: |
| J_DATE: |
| Page: 1 |
| of_pages: 2 |
| Reset: |
| reg38t: 0 |
| A: |
| Contract Line: |
| B: |
| Exhibit: |
| TD: |
| TM: |
| Other: |
| D: |
| System: |
| E: |
| Contract/PR: |
| Contractor: |
| 16: |
| Remarks: |
| Page number: 2 |
| Pages: 2 |
File details come from the government source that posted it. Updated .